Firefox Developer Edition, which is on 40.0, is also reported as vulnerable.
Or is this just not really a browser issue, and held back on the browser side because blocking insecure ciphers breaks most of the internet?
Presumably because the main danger here comes from state-level adversaries who already know and actively exploit the issue, not script kiddies who might get funny ideas after reading the announcement. So the sooner it is published and people can start fixing their servers and clients, the less damage is done.
I finally found the Mozilla bug entry for this, they've known of it since 2010 when they raised the minimums to 512-bit DH groups.