Back to search

Librewolf

Librewolf

See the latest tracked release, confirm when it was published, and subscribe for update emails.

Current version
Last checked: 2026-07-21

153.0-1

Release date
July 21, 2026
Security status
25 high-severity CVEs tracked in the last 90 days. Current version not affected.

Source

Forgejo API

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
153.0-1 2026-07-21 Release Notes
152.0.6-1 2026-07-14 Release Notes
152.0.5-1 2026-07-08 Release Notes
152.0.4-1 2026-07-01 Release Notes
152.0.2-1 2026-06-24 Release Notes
152.0.1-2 2026-06-19 Release Notes
152.0-1 2026-06-16 Release Notes
151.0.4-1 2026-06-09 Release Notes
151.0.3-1 2026-06-03 Release Notes
151.0.2-1 2026-05-28 Release Notes
151.0.1-2 2026-05-23 Release Notes
151.0.1-1 2026-05-22 Release Notes
151.0-1 2026-05-20 Release Notes
150.0.3-1 2026-05-12 Release Notes
150.0.2-1 2026-05-08 Release Notes
150.0.1-1 2026-04-29 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-14241 CRITICAL (9.8) 2026-06-30 Current versionnot affected

Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4.

Affected versions
  • 152.0.3
CVE-2026-12329 HIGH (7.5) 2026-06-16 Current versionnot affected

Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.

Affected versions
  • From (including) 140.0 - Up to (excluding) 140.12.0
CVE-2026-12328 HIGH (8.1) 2026-06-16 Current versionnot affected

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 115.37.0
  • Up to (excluding) 152.0
Show 1 more
  • From (including) 140.0 - Up to (excluding) 140.12.0
CVE-2026-12327 HIGH (8.1) 2026-06-16 Current versionnot affected

Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 115.37.0
  • Up to (excluding) 152.0.0
Show 1 more
  • From (including) 140.0 - Up to (excluding) 140.12.0
CVE-2026-12326 HIGH (8.1) 2026-06-16 Current versionnot affected

Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Affected versions
  • Up to (excluding) 152.0.0
CVE-2026-12324 HIGH (7.3) 2026-06-16 Current versionnot affected

Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 140.12.0
  • Up to (excluding) 152.0.0
CVE-2026-12318 HIGH (7.3) 2026-06-16 Current versionnot affected

Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Affected versions
  • Up to (excluding) 152.0.0
CVE-2026-12317 HIGH (7.5) 2026-06-16 Current versionnot affected

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Affected versions
  • Up to (excluding) 152.0.0
CVE-2026-12316 CRITICAL (9.1) 2026-06-16 Current versionnot affected

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Affected versions
  • Up to (excluding) 152.0.0
CVE-2026-12315 CRITICAL (9.1) 2026-06-16 Current versionnot affected

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 140.12.0
  • Up to (excluding) 152.0.0
CVE-2026-12314 HIGH (7.5) 2026-06-16 Current versionnot affected

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 140.12.0
  • Up to (excluding) 152.0.0
CVE-2026-12312 HIGH (7.5) 2026-06-16 Current versionnot affected

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 140.12.0
  • Up to (excluding) 152.0.0
CVE-2026-12310 HIGH (7.5) 2026-06-16 Current versionnot affected

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 140.12.0
  • Up to (excluding) 152.0.0
CVE-2026-12305 HIGH (7.5) 2026-06-16 Current versionnot affected

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 140.12.0
  • Up to (excluding) 152.0.0
CVE-2026-12304 CRITICAL (9.1) 2026-06-16 Current versionnot affected

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 140.12.0
  • Up to (excluding) 152.0.0
CVE-2026-12299 HIGH (7.5) 2026-06-16 Current versionnot affected

JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 115.37.0
  • Up to (excluding) 152.0
Show 1 more
  • From (including) 140.0 - Up to (excluding) 140.12.0
CVE-2026-12298 HIGH (7.5) 2026-06-16 Current versionnot affected

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 152.0
  • From (including) 140.0 - Up to (excluding) 140.12.0
CVE-2026-12297 CRITICAL (9.6) 2026-06-16 Current versionnot affected

Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 115.37.0
  • Up to (excluding) 152.0.0
Show 1 more
  • From (including) 128.0 - Up to (excluding) 140.12.0
CVE-2026-12296 CRITICAL (9.6) 2026-06-16 Current versionnot affected

Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 140.12.0
  • Up to (excluding) 152.0.0
CVE-2026-12295 CRITICAL (9.6) 2026-06-16 Current versionnot affected

Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 115.37.0
  • Up to (excluding) 152.0.0
Show 1 more
  • From (including) 128.0 - Up to (excluding) 140.12.0
CVE-2026-12294 CRITICAL (9.6) 2026-06-16 Current versionnot affected

Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 115.37.0
  • Up to (excluding) 152.0.0
Show 1 more
  • From (including) 128.0 - Up to (excluding) 140.12.0
CVE-2026-12293 CRITICAL (9.8) 2026-06-16 Current versionnot affected

Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Affected versions
  • Up to (excluding) 152.0.0
CVE-2026-12292 HIGH (8.1) 2026-06-16 Current versionnot affected

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 140.12.0
  • Up to (excluding) 152.0.0
CVE-2026-12291 HIGH (8.8) 2026-06-16 Current versionnot affected

Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 115.37.0
  • Up to (excluding) 152.0.0
Show 1 more
  • From (including) 128.0 - Up to (excluding) 140.12.0
CVE-2026-12290 HIGH (8.1) 2026-06-16 Current versionnot affected

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Affected versions
  • Up to (excluding) 115.37.0
  • Up to (excluding) 152.0.0
Show 1 more
  • From (including) 140.0 - Up to (excluding) 140.12.0