CVE-2026-6746: Use-after-free in the DOM: Core & HTML component
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.35 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 150 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.35 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.10 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 150 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.10
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-6746
- CVE-2026-6749
- CVE-2026-6750
- CVE-2026-6752
- CVE-2026-6754
- CVE-2026-2781
- CVE-2026-6762
- CVE-2026-6767
- CVE-2026-6772
- CVE-2026-6785
- CVE-2026-6747
- CVE-2026-6748
- CVE-2026-6751
- CVE-2026-6753
- CVE-2026-6757
- CVE-2026-6759
- CVE-2026-6761
- CVE-2026-6763
- CVE-2026-6764
- CVE-2026-6765
- CVE-2026-6766
- CVE-2026-6769
- CVE-2026-6770
- CVE-2026-6771
- CVE-2026-6776
- CVE-2026-6786
- CVE-2026-6755
- CVE-2026-6758
- CVE-2026-6760
- CVE-2026-6768
- CVE-2026-6773
- CVE-2026-6774
- CVE-2026-6775
- CVE-2026-6777
- CVE-2026-6778
- CVE-2026-6779
- CVE-2026-6780
- CVE-2026-6781
- CVE-2026-6782
- CVE-2026-6783
- CVE-2026-7321
- CVE-2026-8091
- CVE-2026-6784
- CVE-2026-6756
Frequently Asked Questions
What is the severity of CVE-2026-6746?
CVE-2026-6746 is classified as a high-severity vulnerability due to its potential for exploitation through use-after-free in the DOM.
How do I fix CVE-2026-6746?
To fix CVE-2026-6746, upgrade to Firefox version 150, Firefox ESR version 115.35, or Thunderbird version 150.
What products are affected by CVE-2026-6746?
CVE-2026-6746 affects Mozilla Firefox, Firefox ESR versions below 115.35, and Thunderbird versions below 150.
Is CVE-2026-6746 a remote code execution vulnerability?
CVE-2026-6746 could potentially allow for remote code execution due to its use-after-free nature.
When was CVE-2026-6746 disclosed?
CVE-2026-6746 was disclosed as part of Mozilla's security advisories for the affected products.