HIGH
Denial-of-service in the DOM: Service Workers component
Published Jan 13, 2026
7.5
HIGHCVSS 3.1
EPSS 0.60%
Description
Denial-of-service in the DOM: Service Workers component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
Affected products
No data.
OR
- < 147.0
- < 147.0
No data.
Red Hat Enterprise Linux 10
firefox
Not affected
Red Hat Enterprise Linux 10
rhel10/firefox-flatpak
Not affected
Red Hat Enterprise Linux 6
firefox
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
Red Hat Enterprise Linux 9
firefox
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 10 | rhel10/firefox-flatpak | Not affected | n/a |
| Red Hat Enterprise Linux 6 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 9 | firefox | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Weaknesses (1)
References (8)
- https://access.redhat.com/security/cve/CVE-2026-0889 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1999084 ExploitIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2428964 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-0889
- https://www.cve.org/CVERecord?id=CVE-2026-0889
- https://www.mozilla.org/security/advisories/mfsa2026-01/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-01/#CVE-2026-0889
- https://www.mozilla.org/security/advisories/mfsa2026-04/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-0889 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1999084 | ExploitIssue TrackingVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2428964 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-0889 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-0889 | ||
| https://www.mozilla.org/security/advisories/mfsa2026-01/ | Vendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2026-01/#CVE-2026-0889 | ||
| https://www.mozilla.org/security/advisories/mfsa2026-04/ | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Jan 13, 2026
Updated Apr 13, 2026
Reserved Jan 13, 2026
Link CVE-2026-0889
CISA Vulnrichment
Updated Jan 13, 2026