#VU125088 Buffer overflow in Mozilla products - CVE-2026-5731
Published: April 7, 2026
Mozilla Firefox
Firefox ESR
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-26/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-25/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-27/
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2021894
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022225
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022252
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022294
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2023007
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2023130
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2023191
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2023364
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2023829
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2024074
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2024417
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2024433
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2024436
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2024437
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2024453
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2024461
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2024462
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2024472
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2024474
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2024477
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2025364
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2025401
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2025402
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2025472
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2026287
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2026299
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2026305
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2026426