Back

CRITICAL

Use-after-free in the JavaScript: WebAssembly component

Published Feb 24, 2026

Description

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

Affected products

Remediation

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

Weaknesses (1)

References (38)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mozilla
Published Feb 24, 2026
Updated Jul 15, 2026
Reserved Feb 19, 2026

CISA Vulnrichment

Updated Feb 26, 2026

NVD

Status Modified
Modified Jul 15, 2026

Red Hat

Severity Important
Public date Feb 24, 2026
Bugzilla 2442328

ENISA EUVD

Assigner mozilla
Published Feb 24, 2026
Updated Jul 15, 2026

GitHub

No data