firefox: Sandbox escape due to use-after-free in the DOM: Security component
cve CVE-2026-84121 1 source, 1 claim · Watch
Red Hat writes:
firefox: Sandbox escape due to use-after-free in the DOM: Security component the claim
firefox: Sandbox escape due to use-after-free in the DOM: Security component the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Cvss cvss | Red Hat | 7.5receipt
What the source handed over{
"CVE": "CVE-2026-84121",
"CWE": "CWE-825",
"advisories": [
"RHSA-2026:67129",
"RHSA-2026:67133",
"RHSA-2026:70642",
"RHSA-2026:68549"
],
"affected_packages": [
"thunderbird-0:140.16.0-1.el9_8",
"firefox-0:140.15.0-1.el8_10",
"firefox-0:140.15.0-1.el9_8",
"firefox-0:140.15.0-1.el10_2"
],
"bugzilla": "2526753",
"bugzilla_description": "firefox: Sandbox escape due to use-after-free in the DOM: Security component",
"cvss3_score": "7.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-01T12:18:41Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-84121.json",
"severity": "important"
} | — |
| Cwe cwe | Red Hat | CWE-825receipt
What the source handed over{
"CVE": "CVE-2026-84121",
"CWE": "CWE-825",
"advisories": [
"RHSA-2026:67129",
"RHSA-2026:67133",
"RHSA-2026:70642",
"RHSA-2026:68549"
],
"affected_packages": [
"thunderbird-0:140.16.0-1.el9_8",
"firefox-0:140.15.0-1.el8_10",
"firefox-0:140.15.0-1.el9_8",
"firefox-0:140.15.0-1.el10_2"
],
"bugzilla": "2526753",
"bugzilla_description": "firefox: Sandbox escape due to use-after-free in the DOM: Security component",
"cvss3_score": "7.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-01T12:18:41Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-84121.json",
"severity": "important"
} | — |
| Packages packages | Red Hat | thunderbird-0:140.16.0-1.el9_8, firefox-0:140.15.0-1.el8_10, firefox-0:140.15.0-1.el9_8, firefox-0:140.15.0-1.el10_2receipt
What the source handed over{
"CVE": "CVE-2026-84121",
"CWE": "CWE-825",
"advisories": [
"RHSA-2026:67129",
"RHSA-2026:67133",
"RHSA-2026:70642",
"RHSA-2026:68549"
],
"affected_packages": [
"thunderbird-0:140.16.0-1.el9_8",
"firefox-0:140.15.0-1.el8_10",
"firefox-0:140.15.0-1.el9_8",
"firefox-0:140.15.0-1.el10_2"
],
"bugzilla": "2526753",
"bugzilla_description": "firefox: Sandbox escape due to use-after-free in the DOM: Security component",
"cvss3_score": "7.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-01T12:18:41Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-84121.json",
"severity": "important"
} | — |
| Severity severity | Red Hat | important A flaw that can easily compromise confidentiality, integrity or availability. receipt
What the source handed over{
"CVE": "CVE-2026-84121",
"CWE": "CWE-825",
"advisories": [
"RHSA-2026:67129",
"RHSA-2026:67133",
"RHSA-2026:70642",
"RHSA-2026:68549"
],
"affected_packages": [
"thunderbird-0:140.16.0-1.el9_8",
"firefox-0:140.15.0-1.el8_10",
"firefox-0:140.15.0-1.el9_8",
"firefox-0:140.15.0-1.el10_2"
],
"bugzilla": "2526753",
"bugzilla_description": "firefox: Sandbox escape due to use-after-free in the DOM: Security component",
"cvss3_score": "7.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-01T12:18:41Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-84121.json",
"severity": "important"
} | high |
vulnerability
| firefox: Sandbox escape due to use-after-free in the DOM: Security component zetlyn/cve-redhat · 2026-09-01 | cvss 7.5 cwe CWE-825 packages thunderbird-0:140.16.0-1.el9_8, firefox-0:140.15.0-1.el8_10, firefox-0:140.15.0-1.el9_8, firefox-0:140.15.0-1.el10_2 severity important | source |