Use-After-Free Vulnerability in Firefox XSLT Component
CVE-2026-100790

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100790?

A use-after-free vulnerability exists in the XSLT component of Firefox, potentially leading to memory corruption and exploitation by attackers. This issue has been addressed in multiple versions, including Firefox ESR 153.4, Firefox 157, and others. Users are urged to update to the latest versions to mitigate risks associated with this vulnerability.

Affected Version(s)

Firefox 115.42

Firefox 140.17

Firefox 153.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.