Opened 6 weeks ago
Closed 6 weeks ago
#23769 closed enhancement (fixed)
spidermonkey (js) 140.14.0esr
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | high | Keywords: | |
| Cc: |
Description
These are the security fixes related to js in the Firefox advisory instead of listing all 31:
- CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component (high)
- CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component (low)
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/
Change History (2)
comment:1 by , 6 weeks ago
| Milestone: | 13.1 → 98-Security |
|---|---|
| Owner: | changed from to |
| Status: | assigned → new |
comment:2 by , 6 weeks ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.0-204 has been issued.
Note:
See TracTickets
for help on using tickets.

Fixed at a94c733b1d. Leaving open for SA.