Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
Update Mozilla/Firefox to 74.0.1; Mozilla/Firefox ESR to 68.6.1; Mozilla/Thunderbird to 68.7.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCVE Program Container affects Mozilla/Firefox (generic), Mozilla/Firefox ESR (generic), Mozilla/Thunderbird (generic). Severity is high. This vulnerability is known to be exploited in the wild. Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Mozilla/Firefoxgeneric | >=unspecified <74.0.1 | 74.0.1 |
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
Update Mozilla/Firefox to 74.0.1; Mozilla/Firefox ESR to 68.6.1; Mozilla/Thunderbird to 68.7.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCVE Program Container affects Mozilla/Firefox (generic), Mozilla/Firefox ESR (generic), Mozilla/Thunderbird (generic). Severity is high. This vulnerability is known to be exploited in the wild. Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Mozilla/Firefoxgeneric | >=unspecified <74.0.1 | 74.0.1 |
| Mozilla/Firefox ESRgeneric | >=unspecified <68.6.1 | 68.6.1 |
|---|
| Mozilla/Thunderbirdgeneric | >=unspecified <68.7.0 | 68.7.0 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Mozilla/Firefox ESRgeneric | >=unspecified <68.6.1 | 68.6.1 |
|---|
| Mozilla/Thunderbirdgeneric | >=unspecified <68.7.0 | 68.7.0 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard