CVE-2026-6766
Boundary Error in NSS Libraries Causes Potential Security Risk
Publication date: 2026-04-21
Last updated on: 2026-04-22
Assigner: Mozilla Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mozilla | firefox | to 150.0 (exc) |
| mozilla | firefox | to 140.10.0 (exc) |
| mozilla | thunderbird | to 140.10.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-754 | The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves incorrect boundary conditions in the Libraries component of NSS (Network Security Services). It means that certain checks or limits within the code were not properly enforced, potentially leading to unexpected behavior or security issues.
The issue was addressed and fixed in Firefox version 150 and Firefox ESR 140.10.
What immediate steps should I take to mitigate this vulnerability?
The vulnerability was fixed in Firefox 150 and Firefox ESR 140.10. To mitigate this vulnerability, you should update your Firefox or Firefox ESR browsers to at least these versions.
How can this vulnerability impact me? :
This vulnerability involves incorrect boundary conditions in the Libraries component of NSS, which could potentially lead to security issues in affected versions of Mozilla Firefox and Firefox ESR before the fixes were applied.
It was fixed in Firefox 150 and Firefox ESR 140.10, so using versions prior to these may expose you to risks related to this vulnerability.