Critical severity9.8NVD Advisory· Published May 7, 2026· Updated May 11, 2026
CVE-2026-8091
CVE-2026-8091
Description
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.
Affected products
2- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*Range: >=140.0,<140.10.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.mozilla.org/security/advisories/mfsa2026-30/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2026-33/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2026-36/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2026-39/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2026-42/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdPermissions Required
News mentions
0No linked articles in our index yet.