{"id":"CVE-2022-26485","title":"Removing an XSLT parameter during processing could have lead to an exploitable use-after-free","summary":"Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for A…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-416","CWE-416"],"vendor":"mozilla","product":"firefox","affected":["firefox < 91.6.1","firefox < 97.0.2","firefox_focus < 97.3.0","firefox_mobile < 97.3.0","thunderbird < 91.6.2"],"patched":["firefox 97.0.2","firefox_focus 97.3.0","firefox_mobile 97.3.0","thunderbird 91.6.2"],"published":"2022-12-22","updated":"2026-08-19","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-26485","references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1758062","label":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2022-09/","label":"security@mozilla.org"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1758062","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.mozilla.org/security/advisories/mfsa2022-09/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26485","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.14261,"epssPercentile":0.96487,"kev":true,"kevDateAdded":"2022-03-07","kevDueDate":"2022-03-21","kevRansomware":false,"exploited":true,"zeroDay":true,"ingestedAt":"2026-08-19T15:41:15.226Z","exploits":{"github":1,"githubRepos":["https://github.com/mistymntncop/CVE-2022-26485"],"checkedAt":"2026-09-21T15:25:17.891Z"},"exploitAvailable":true,"slug":"CVE-2022-26485","body":"## Overview\n\nRemoving an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.\n\n## Affected\n\n- `firefox < 91.6.1`\n- `firefox < 97.0.2`\n- `firefox_focus < 97.3.0`\n- `firefox_mobile < 97.3.0`\n- `thunderbird < 91.6.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `firefox 97.0.2`\n- `firefox_focus 97.3.0`\n- `firefox_mobile 97.3.0`\n- `thunderbird 91.6.2`","depth":"abyssal","depthScore":76,"depthScoreParts":{"impact":48.4,"likelihood":2.9,"exploitation":25,"ransomware":0},"changes":[{"seq":4605,"id":"CVE-2022-26485","ts":1788887193794,"field":"exploit_available","old":"false","new":"true"},{"seq":3488,"id":"CVE-2022-26485","ts":1788886310215,"field":"exploit_available","old":"true","new":"false"},{"seq":2342,"id":"CVE-2022-26485","ts":1788882979717,"field":"exploit_available","old":"false","new":"true"},{"seq":1371,"id":"CVE-2022-26485","ts":1788882392314,"field":"exploit_available","old":"true","new":"false"},{"seq":485,"id":"CVE-2022-26485","ts":1788881827938,"field":"exploit_available","old":"false","new":"true"}]}