CVE-2026-2806: Uninitialized memory in the Graphics: Text component
Published Feb 24, 2026
·Updated
Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
Affected Software
4 affected componentsFixes available
Mozilla Firefox<148
148
Mozilla Thunderbird<148
148
Mozilla Firefox<148.0
Mozilla Thunderbird<148.0
Event History
Feb 24, 2026
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
Description
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Jan 4, 58137
Event
via FIRST·07:25 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-2757
- CVE-2026-2794
- CVE-2026-2758
- CVE-2026-2759
- CVE-2026-2795
- CVE-2026-2760
- CVE-2026-2761
- CVE-2026-2762
- CVE-2026-2763
- CVE-2026-2764
- CVE-2026-2796
- CVE-2026-2797
- CVE-2026-2765
- CVE-2026-2766
- CVE-2026-2767
- CVE-2026-2768
- CVE-2026-2798
- CVE-2026-2769
- CVE-2026-2799
- CVE-2026-2770
- CVE-2026-2771
- CVE-2026-2772
- CVE-2026-2773
- CVE-2026-2774
- CVE-2026-2775
- CVE-2026-2776
- CVE-2026-2777
- CVE-2026-2778
- CVE-2026-2779
- CVE-2026-2800
- CVE-2026-2780
- CVE-2026-2781
- CVE-2026-2801
- CVE-2026-2782
- CVE-2026-2783
- CVE-2026-2802
- CVE-2026-2803
- CVE-2026-2784
- CVE-2026-2785
- CVE-2026-2804
- CVE-2026-2786
- CVE-2026-2805
- CVE-2026-2787
- CVE-2026-2788
- CVE-2026-2789
- CVE-2026-2806
- CVE-2026-2790
- CVE-2026-2791
- CVE-2026-2807
- CVE-2026-2792
- CVE-2026-2793
Frequently Asked Questions
1
What is the severity of CVE-2026-2806?
CVE-2026-2806 is categorized as a moderate severity vulnerability affecting Firefox versions prior to 148.
2
How do I fix CVE-2026-2806?
To fix CVE-2026-2806, upgrade your Firefox browser to version 148 or later.
3
What is the impact of CVE-2026-2806?
The impact of CVE-2026-2806 involves the potential exposure of uninitialized memory in the Graphics: Text component, which could lead to information disclosure.
4
Which versions of Firefox are affected by CVE-2026-2806?
CVE-2026-2806 affects all versions of Firefox prior to 148.
5
Who is the vendor for CVE-2026-2806?
The vendor for CVE-2026-2806 is Mozilla.