CVE-2026-4688: NixOS vulnerability analysis and mitigation
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Source: NVD
Related NixOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-24660
CRITICAL
9.8
NixOS
LibRaw-static
No
Yes
Apr 07, 2026
CVE-2026-24450
CRITICAL
9.8
NixOS
LibRaw-devel
No
Yes
Apr 07, 2026
CVE-2026-21413
CRITICAL
9.8
NixOS
LibRaw-devel
No
Yes
Apr 07, 2026
CVE-2026-39883
HIGH
7.3
Packer
thanos
No
Yes
Apr 08, 2026
CVE-2026-39882
MEDIUM
5.3
Prometheus
frankenphp-8.3
No
Yes
Apr 08, 2026
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.