CVE-2026-12325
published 2026-06-16CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152…
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.23%
13.5th percentile
Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 152 | Firefox 152 |
| mozilla | firefox | — | — |
| mozilla | firefox_esr | < Firefox ESR 115.37 | Firefox ESR 115.37 |
| mozilla | firefox_esr | < Firefox ESR 140.12 | Firefox ESR 140.12 |
| mozilla | thunderbird | < Thunderbird 152 | Thunderbird 152 |
| mozilla | thunderbird | < Thunderbird 140.12 | Thunderbird 140.12 |
| mozilla | thunderbird | — | — |
| rhel10 | firefox-flatpak | — | — |
| rhel10 | thunderbird-flatpak | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Firefox up to 151 ImageLib denial of service (Nessus ID 321490 / WID-SEC-2026-1959)
vuldb·2026-07-10·CVSS 6.5
CVE-2026-12325 [MEDIUM] Mozilla Firefox up to 151 ImageLib denial of service (Nessus ID 321490 / WID-SEC-2026-1959)
A vulnerability categorized as problematic has been discovered in Mozilla Firefox up to 151. This vulnerability affects unknown code of the component ImageLib. Such manipulation leads to denial of service.
This vulnerability is referenced as CVE-2026-12325. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
Denial-of-service in the Graphics: ImageLib component.
ghsa_unreviewed·2026-06-16
CVE-2026-12325 [MEDIUM] CWE-400 Denial-of-service in the Graphics: ImageLib component.
Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.
Red Hat
firefox: thunderbird: Denial-of-service in the Graphics: ImageLib component
vendor_redhat·2026-06-16·CVSS 6.5
CVE-2026-12325 [MEDIUM] CWE-1286 firefox: thunderbird: Denial-of-service in the Graphics: ImageLib component
firefox: thunderbird: Denial-of-service in the Graphics: ImageLib component
Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:
Denial-of-service in the Graphics: ImageLib component
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Affected
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux 10) - Affected
Package: rhel10/thunderbird-flatpak (Red Hat Enterprise Linux 10) - Affected
Package: thunderbird (Red Ha
Mozilla
Mozilla Foundation Security Advisory 2026-59: CVE-2026-12325
vendor_mozilla·CVSS 6.5
CVE-2026-12325 [MEDIUM] Mozilla Foundation Security Advisory 2026-59: CVE-2026-12325
Mozilla Foundation Security Advisory 2026-59
CVE: CVE-2026-12325
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.37
Mozilla
Mozilla Foundation Security Advisory 2026-60: CVE-2026-12325
vendor_mozilla·CVSS 6.5
CVE-2026-12325 [MEDIUM] Mozilla Foundation Security Advisory 2026-60: CVE-2026-12325
Mozilla Foundation Security Advisory 2026-60
CVE: CVE-2026-12325
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 152
Mozilla
Mozilla Foundation Security Advisory 2026-61: CVE-2026-12325
vendor_mozilla·CVSS 6.5
CVE-2026-12325 [MEDIUM] Mozilla Foundation Security Advisory 2026-61: CVE-2026-12325
Mozilla Foundation Security Advisory 2026-61
CVE: CVE-2026-12325
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.12
Mozilla
Mozilla Foundation Security Advisory 2026-57: CVE-2026-12325
vendor_mozilla·CVSS 6.5
CVE-2026-12325 [MEDIUM] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12325
Mozilla Foundation Security Advisory 2026-57
CVE: CVE-2026-12325
Product: Firefox
Impact: high
Fixed in: Firefox 152
Mozilla
Mozilla Foundation Security Advisory 2026-58: CVE-2026-12325
vendor_mozilla·CVSS 6.5
CVE-2026-12325 [MEDIUM] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12325
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12325
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
No detection rules found.
No public exploits indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=2039443https://www.mozilla.org/security/advisories/mfsa2026-57/https://www.mozilla.org/security/advisories/mfsa2026-58/https://www.mozilla.org/security/advisories/mfsa2026-59/https://www.mozilla.org/security/advisories/mfsa2026-60/https://www.mozilla.org/security/advisories/mfsa2026-61/
2026-06-16
Published