← Back to browse · API

CVE-2025-4918

Severity
CRITICAL
CVSS
9.8
EPSS
0.08987
Risk score
42.35
CISA KEV
No
PoC
No
Published
2025-05-17
Modified
2026-04-13
First seen
2026-08-07
Aliases
EUVD-2025-15599, GHSA-FHGM-MXGH-GFPJ
Products
-
Sources
euvd EUVD-2025-15599

Description

An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1, Thunderbird 128.10.2, and Thunderbird 138.0.2.

References