CVE-2026-2794Use of Uninitialized Resource in Mozilla Firefox

Severity
7.5HIGHNVD
EPSS
0.0%
top 88.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 24

Description

Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 148.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDmozilla/firefox< 148.0

🔴Vulnerability Details

3
GHSA
GHSA-m8jj-q5xq-4qhp: Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android2026-02-24
OSV
CVE-2026-2794: Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android2026-02-24
CVEList
Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android2026-02-24

📋Vendor Advisories

3
Red Hat
firefox: Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android2026-02-24
Debian
CVE-2026-2794: firefox - Information disclosure due to uninitialized memory in Firefox and Firefox Focus ...2026
Mozilla
Mozilla Foundation Security Advisory 2026-13: CVE-2026-2794

🕵️Threat Intelligence

1
Wiz
CVE-2026-2794 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-2794 — Use of Uninitialized Resource | cvebase