CVE-2026-6781
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-6781 is a denial-of-service vulnerability in the Audio/Video: Playback component of Mozilla Firefox and Thunderbird. Reported by researcher "LatticeBased" and disclosed on April 21, 2026, it affects all versions of Firefox and Thunderbird prior to 150.0. The vulnerability carries a CVSS v3.1 base score of 7.5 (High), assessed by CISA-ADP, with no confidentiality or integrity impact but high availability impact (Mozilla Advisory, Github Advisory).

Technical details

The root cause is classified as CWE-400 (Uncontrolled Resource Consumption) and CWE-770 (Allocation of Resources Without Limits or Throttling), indicating the Audio/Video Playback component fails to properly limit resource allocation when processing certain media content (Github Advisory). The vulnerability is exploitable remotely over the network with low attack complexity, requiring no privileges and no user interaction, suggesting that a maliciously crafted media resource served to a vulnerable browser or email client could trigger the condition. The underlying Mozilla bug report is tracked at Bugzilla bug 2025583, though the bug details are access-restricted (Mozilla Advisory).

Impact

Successful exploitation causes a denial-of-service condition in the affected Firefox or Thunderbird application, resulting in high availability impact with no confidentiality or integrity loss. An attacker could cause the browser or email client to become unresponsive or crash by delivering specially crafted audio/video content, disrupting the end user's session. There is no evidence of lateral movement potential or data exposure risk associated with this vulnerability (Github Advisory, Mozilla Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-6781. The EPSS score is approximately 0.038–0.057%, placing it in a low exploitation probability range (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified.

Mitigation and workarounds

Mozilla has released fixed versions addressing this vulnerability: Firefox 150 and Thunderbird 150. Users and administrators should update to these versions or later immediately. No configuration-based workarounds have been published; upgrading is the only recommended remediation (Mozilla Advisory, Mozilla Thunderbird Advisory).

Community reactions

The CIS published an advisory noting multiple vulnerabilities in Mozilla products fixed in this release cycle, including CVE-2026-6781, framing the broader Firefox 150 update as addressing risks up to arbitrary code execution. Security news outlets including GBHackers and CyberPress covered the Firefox 150 release, highlighting the range of fixes. No notable individual researcher commentary specific to CVE-2026-6781 has been identified, consistent with its low-impact classification within the broader advisory.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

sid

firefox: 150.0-1

Fixed

Ubuntu

Affected

bionic (esm-apps)

mozjs38

Unknown

devel

firefox

Not Affected

jammy

thunderbird

Affected

noble

firefox

Not Affected

questing

firefox

Not Affected

resolute

firefox

Not Affected

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

Not Affected

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management