Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 22 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla thunderbird
|
|
| CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:* |
|
| Vendors & Products |
Mozilla thunderbird
|
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-807 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150. | Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
| References |
|
Tue, 21 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla firefox |
|
| Vendors & Products |
Mozilla
Mozilla firefox |
Tue, 21 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
cvssV3_1
|
Tue, 21 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150. | |
| Title | Mitigation bypass in the DOM: postMessage component | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-04-21T23:34:47.512Z
Reserved: 2026-04-21T12:40:51.062Z
Link: CVE-2026-6755
Updated: 2026-04-21T13:47:11.033Z
Status : Analyzed
Published: 2026-04-21T13:16:21.510
Modified: 2026-04-22T16:08:14.983
Link: CVE-2026-6755
OpenCVE Enrichment
Updated: 2026-04-22T13:45:18Z