Official source evidencewww.mozilla.orgVersioned article
Official source article · www.mozilla.org

Security Vulnerabilities fixed in Firefox ESR 115.37 — Mozilla

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherwww.mozilla.org
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 08:14 UTC
Linked CVEs11

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-12328Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152
  • CVE-2026-12299JIT miscompilation in the DOM: Core & HTML component
  • CVE-2026-12297Sandbox escape due to incorrect boundary conditions in the Networking component
  • CVE-2026-12295Sandbox escape in the DOM: Navigation component
  • CVE-2026-12294Sandbox escape in the DOM: Workers component
  • CVE-2026-12291Use-after-free in the Networking: HTTP component
  • CVE-2026-12290Memory safety bug fixed in Firefox 152
  • CVE-2026-12289Privilege escalation in the Graphics: WebRender component
  • CVE-2026-12302Mitigation bypass in the DOM: Security component
  • CVE-2026-12330Incorrect boundary conditions in the Internationalization component
  • CVE-2026-12325Denial-of-service in the Graphics: ImageLib component

Source and provenance

Original title: Security Vulnerabilities fixed in Firefox ESR 115.37 — Mozilla. Captured 29 Sept 2026, 08:14 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗