CVE-2026-4705 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 25, 2026
Firefox - Undefined Behavior
Overview
Firefox < 149 and Firefox ESR < 140.9 contain an undefined behavior vulnerability in the WebRTC: Signaling component, letting attackers potentially cause unexpected behavior, exploit requires no special conditions.
Severity & Score
Impact
Attackers can cause undefined behavior in the WebRTC signaling component, potentially leading to application instability or other unknown impacts.
Mitigation
Update to Firefox 149, Firefox ESR 140.9 or later.
References
Social Media Activity(1 post)
š“ CVE-2026-4705 - Critical (9.8) Undefined behavior in the WebRTC: Signaling component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9. š https://www.thehackerwire.com/vulnerability/CVE-2026-4705/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-4705
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- undefined
- Status
- modified
- EPSS
- 1.6%
- Social Posts
- 1
CWE
- NVD-CWE-noinfo
- CWE-758
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H