
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-12325 is a denial-of-service vulnerability in the Graphics: ImageLib component of Mozilla Firefox and Thunderbird, classified as low severity by Mozilla. It was discovered by Securin and disclosed on June 16, 2026, as part of Mozilla's coordinated security advisory release. Affected products include Firefox before 152, Firefox ESR before 140.12 (in the 140.x branch), Firefox ESR before 115.37 (in the 115.x branch), Thunderbird before 152, and Thunderbird ESR before 140.12. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (Mozilla Advisory mfsa2026-57, Mozilla Advisory mfsa2026-58, Mozilla Advisory mfsa2026-59).
The vulnerability is rooted in uncontrolled resource consumption (CWE-400) and improper validation of syntactic correctness of input (CWE-1286) within Firefox's and Thunderbird's image processing library (ImageLib). An attacker can craft a malicious image file or serve one via a web page that, when processed by the browser or email client, triggers excessive resource consumption leading to application crash or hang. Exploitation requires user interaction — specifically, a victim must visit a malicious web page or open a crafted email/attachment — and no authentication or elevated privileges are required on the attacker's side. The underlying bug is tracked as Mozilla Bug 2039443, though the bug report is access-restricted (Mozilla Advisory mfsa2026-57, Mozilla Advisory mfsa2026-59).
Successful exploitation causes a denial-of-service condition, crashing or hanging the affected Firefox or Thunderbird application. The impact is limited to availability — there is no confidentiality or integrity impact, and the vulnerability does not enable code execution, data exfiltration, or lateral movement. End users would experience browser or email client crashes when encountering a specially crafted image, requiring a restart of the application (Mozilla Advisory mfsa2026-57, Mozilla Advisory mfsa2026-58).
Mozilla has released patched versions addressing this vulnerability: Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird ESR 140.12. Users and administrators should update to these versions or later immediately. No configuration-based workarounds have been published; upgrading is the only recommended remediation. Enterprise deployments using Red Hat, SUSE, openSUSE, AlmaLinux, Oracle Linux, Debian, or Slackware should apply the corresponding vendor-provided package updates (Mozilla Advisory mfsa2026-57, Mozilla Advisory mfsa2026-58, Mozilla Advisory mfsa2026-59).
The vulnerability was reported to Mozilla by Securin and disclosed as part of a broader June 16, 2026 security advisory batch covering 44 vulnerabilities across Firefox and Thunderbird. The CIS issued an advisory noting multiple vulnerabilities in Mozilla products could allow for arbitrary code execution (referring to the broader advisory set). Downstream Linux distributions including Red Hat, SUSE, openSUSE, AlmaLinux, Oracle Linux, and Debian have all issued update advisories. Community and media reaction has been minimal given the low severity rating of this specific CVE relative to the higher-severity issues in the same advisory batch (Mozilla Advisory mfsa2026-57, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."