CVE-2026-12325: Vulnerability in Mozilla Firefox
CVE-2026-12325 is a denial-of-service vulnerability in the Graphics: ImageLib component of Mozilla Firefox. It affects Firefox versions prior to 152, Firefox ESR versions up to 140.11, and ESR 115.36 and earlier. The vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37. The CVSS score is 6.5 (medium severity), indicating a network-exploitable issue that requires user interaction and results in denial of service without confidentiality or integrity impact.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-12325) involves a denial-of-service condition in the Graphics: ImageLib component of Mozilla Firefox. It affects Firefox versions before 152, Firefox ESR versions up to 140.11, and ESR 115.36 and earlier. The issue was resolved in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37. The CVSS 3.1 vector indicates the attack can be performed remotely over the network with low attack complexity, no privileges required, but requires user interaction. The impact is limited to availability (denial of service) without affecting confidentiality or integrity. Mozilla has published official security advisories detailing the fix and recommending updates.
Potential Impact
Successful exploitation of this vulnerability can cause a denial-of-service condition in affected Firefox versions, potentially crashing the browser or rendering it unusable. There is no direct impact on confidentiality or integrity. The vulnerability is remotely exploitable and requires user interaction.
Mitigation Recommendations
Mozilla has fixed this vulnerability in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37. Users and administrators should update affected Firefox installations to these versions or later to remediate the issue. No additional mitigation steps are indicated by the vendor advisories. Patch status is confirmed by Mozilla advisories.
CVE-2026-12325: Vulnerability in Mozilla Firefox
Description
CVE-2026-12325 is a denial-of-service vulnerability in the Graphics: ImageLib component of Mozilla Firefox. It affects Firefox versions prior to 152, Firefox ESR versions up to 140.11, and ESR 115.36 and earlier. The vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37. The CVSS score is 6.5 (medium severity), indicating a network-exploitable issue that requires user interaction and results in denial of service without confidentiality or integrity impact.
CVSS v3.1
Score 6.5medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-12325) involves a denial-of-service condition in the Graphics: ImageLib component of Mozilla Firefox. It affects Firefox versions before 152, Firefox ESR versions up to 140.11, and ESR 115.36 and earlier. The issue was resolved in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37. The CVSS 3.1 vector indicates the attack can be performed remotely over the network with low attack complexity, no privileges required, but requires user interaction. The impact is limited to availability (denial of service) without affecting confidentiality or integrity. Mozilla has published official security advisories detailing the fix and recommending updates.
Potential Impact
Successful exploitation of this vulnerability can cause a denial-of-service condition in affected Firefox versions, potentially crashing the browser or rendering it unusable. There is no direct impact on confidentiality or integrity. The vulnerability is remotely exploitable and requires user interaction.
Mitigation Recommendations
Mozilla has fixed this vulnerability in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37. Users and administrators should update affected Firefox installations to these versions or later to remediate the issue. No additional mitigation steps are indicated by the vendor advisories. Patch status is confirmed by Mozilla advisories.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mozilla
- Date Reserved
- 2026-06-15T15:08:21.546Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://www.mozilla.org/security/advisories/mfsa2026-57/","vendor":"Mozilla"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-58/","vendor":"Mozilla"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-59/","vendor":"Mozilla"}]
Threat ID: 6a314c830b89be6888b4cddb
Added to database: 06/16/2026, 13:15:47 UTC
Last enriched: 06/23/2026, 15:20:03 UTC
Last updated: 08/01/2026, 07:17:58 UTC
Views: 69
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.