{"id":"ALSA-2026:49922","summary":"Important: thunderbird security update","details":"Mozilla Thunderbird is a standalone mail and newsgroup client.  \n\nSecurity Fix(es):  \n\n  * firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719)\n  * firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718)\n  * firefox: thunderbird: Mitigation bypass in the Enterprise Policies component (CVE-2026-16390)\n  * firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: cubeb component (CVE-2026-16350)\n  * firefox: thunderbird: Information disclosure in the Storage: IndexedDB component (CVE-2026-16391)\n  * firefox: thunderbird: Site isolation issue in the Networking: HTTP component (CVE-2026-16375)\n  * firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16356)\n  * firefox: thunderbird: JIT miscompilation in the JavaScript: WebAssembly component (CVE-2026-16363)\n  * firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 (CVE-2026-16412)\n  * firefox: thunderbird: Same-origin policy bypass in the Networking: DNS component (CVE-2026-16381)\n  * firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-16355)\n  * firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 (CVE-2026-16361)\n  * firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16352)\n  * firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component (CVE-2026-16368)\n  * firefox: thunderbird: Mitigation bypass in the PDF Viewer component (CVE-2026-16377)\n  * firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 (CVE-2026-16360)\n  * firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component (CVE-2026-16362)\n  * firefox: thunderbird: Site isolation issue in the Graphics: WebRender component (CVE-2026-16358)\n  * firefox: thunderbird: Site isolation issue in the Networking component (CVE-2026-16387)\n  * firefox: thunderbird: Same-origin policy bypass in the DOM: Navigation component (CVE-2026-16349)\n  * firefox: thunderbird: Incorrect boundary conditions in the Graphics component (CVE-2026-16357)\n  * firefox: thunderbird: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-16351)\n  * firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-16371)\n  * firefox: thunderbird: Privilege escalation in the DOM: Content Processes component (CVE-2026-16379)\n  * firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-16354)\n  * firefox: thunderbird: Information disclosure in the Framework component in DevTools (CVE-2026-16374)\n  * firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: GMP component (CVE-2026-16359)\n  * firefox: thunderbird: Mitigation bypass in the DOM: Networking component (CVE-2026-16383)\n  * firefox: thunderbird: Integer overflow in the JavaScript: WebAssembly component (CVE-2026-16369)\n  * firefox: thunderbird: Invalid pointer in the DOM: Bindings (WebIDL) component (CVE-2026-16353)\n  * firefox: thunderbird: Privilege escalation in WebExtensions (CVE-2026-16396)\n  * firefox: thunderbird: Information disclosure in the Networking: WebSockets component (CVE-2026-16405)\n  * thunderbird: Off-by-one out of bounds read in MIME header parser for forwarding (CVE-2026-14899)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n","modified":"2026-08-04T19:12:16.403618768Z","published":"2026-08-04T00:00:00Z","related":["CVE-2026-14899","CVE-2026-15718","CVE-2026-15719","CVE-2026-16349","CVE-2026-16350","CVE-2026-16351","CVE-2026-16352","CVE-2026-16353","CVE-2026-16354","CVE-2026-16355","CVE-2026-16356","CVE-2026-16357","CVE-2026-16358","CVE-2026-16359","CVE-2026-16360","CVE-2026-16361","CVE-2026-16362","CVE-2026-16363","CVE-2026-16368","CVE-2026-16369","CVE-2026-16371","CVE-2026-16374","CVE-2026-16375","CVE-2026-16377","CVE-2026-16379","CVE-2026-16381","CVE-2026-16383","CVE-2026-16387","CVE-2026-16390","CVE-2026-16391","CVE-2026-16396","CVE-2026-16405","CVE-2026-16412"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:49922"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14899"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-15718"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-15719"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16349"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16350"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16351"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16352"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16353"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16354"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16355"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16356"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16357"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16358"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16359"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16360"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16361"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16362"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16363"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16368"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16369"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16371"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16374"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16375"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16377"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16379"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16381"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16383"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16387"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16390"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16391"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16396"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16405"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16412"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2499973"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2499974"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503415"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503416"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503420"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503423"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503425"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503430"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503432"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503434"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503439"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503440"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503444"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503451"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503454"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503456"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503463"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503472"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503473"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503485"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503489"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503491"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503497"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503498"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503500"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503501"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503505"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503512"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503513"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503517"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503521"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2503527"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2506217"},{"type":"ADVISORY","url":"https://errata.almalinux.org/8/ALSA-2026-49922.html"}],"affected":[{"package":{"name":"thunderbird","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/thunderbird"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.13.0-1.el8_10.alma.1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:49922.json"}}],"schema_version":"1.8.0"}