CVE-2026-8389
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.
CVSS
8.8
High
EPSS
0.3%
p26
KEV
—
Exploit Today
8
0-100
Published: May 12, 2026 · Last modified: Jul 15, 2026 · CWE-119 · CWE-686 · CWE-843
0.3%EPSS · 30 days0.3%
2026-08-172026-09-14
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2036983
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-45/
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-8389
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2476466
- github.comhttps://github.com/crixpwn/CVE-2026-8389
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8389.json
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-920548.8 HIG—
———Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.8hCVE-2026-910914.3 MED—
——0A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is sufficient to resolve this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.6hCVE-2026-910903.9 LOW—
——0A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is sufficient to fix this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. The affected component should be upgraded.7hCVE-2026-910896.3 MED—
——0A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version abi-16.23 is recommended to address this issue. The patch is identified as 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.3hCVE-2026-910884.8 MED—
——0A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. Upgrading to version abi-16.23 is capable of addressing this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. It is advisable to upgrade the affected component.6hCVE-2026-910877.3 HIG—
——0A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can lead to use after free. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version abi-16.24 is able to resolve this issue. This patch is called e34f4ba349d55cd1849f0bcf4cf46552732e2db7. Upgrading the affected component is advised.7h