Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.