{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2026-6746: HTMLSlotElement - fix manual slot reassignment across different shadow roots (Bug 2014596)\n- CVE-2026-6749: ImageEncoder use mapped stride and surface size to avoid OOB read (Bug 2022610)\n- CVE-2026-6752: libwebrtc - truncate RTP CSRC list to RFC 3550 spec maximum (15)\n- CVE-2026-6785: prevent use-after-free in nsUnknownDecoder::CheckListenerChain (Bug 2036929)\n- CVE-2026-8388: SpiderMonkey JIT - widen RecoverOffset to uint64_t to prevent overflow in Ion snapshot encoding (Bug 2036978)",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/almalinux9.2esu/advisories/2026/clsa-2026_1780952647.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-06-09T08:39:35Z",
      "generator": {
        "date": "2026-06-09T08:39:35Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1780952647",
      "initial_release_date": "2026-06-08T21:05:08Z",
      "revision_history": [
        {
          "date": "2026-06-08T21:05:08Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-09T08:39:35Z",
          "number": "2",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "thunderbird: Fix of 2 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "AlmaLinux 9.2",
                "product": {
                  "name": "AlmaLinux 9.2",
                  "product_id": "AlmaLinux-9.2",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:almalinux:almalinux:9.2:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "AlmaLinux"
          }
        ],
        "category": "vendor",
        "name": "AlmaLinux OS Foundation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64",
                "product": {
                  "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64",
                  "product_id": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/thunderbird@115.4.1-1.el9_2.alma.tuxcare.els9?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
                "product": {
                  "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
                  "product_id": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/thunderbird@115.4.1-1.el9_2.alma.tuxcare.els4?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
                "product": {
                  "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
                  "product_id": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/thunderbird@115.4.1-1.el9_2.alma.tuxcare.els3?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
                "product": {
                  "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
                  "product_id": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/thunderbird@115.4.1-1.el9_2.alma.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        },
        "product_reference": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
        },
        "product_reference": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64"
        },
        "product_reference": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64"
        },
        "product_reference": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-6769",
      "cwe": {
        "id": "CWE-266",
        "name": "Incorrect Privilege Assignment"
      },
      "notes": [
        {
          "category": "description",
          "text": "Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-6769"
        }
      ],
      "release_date": "2026-04-21T12:41:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-08T21:04:10.415162Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647"
        },
        {
          "category": "none_available",
          "date": "2026-04-21T12:41:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-6754",
      "cwe": {
        "id": "CWE-825",
        "name": "Expired Pointer Dereference"
      },
      "notes": [
        {
          "category": "description",
          "text": "Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-6754"
        }
      ],
      "release_date": "2026-04-21T12:40:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-08T21:04:10.415162Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647"
        },
        {
          "category": "none_available",
          "date": "2026-04-21T12:40:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-6750",
      "cwe": {
        "id": "CWE-266",
        "name": "Incorrect Privilege Assignment"
      },
      "notes": [
        {
          "category": "description",
          "text": "Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-6750"
        }
      ],
      "release_date": "2026-04-21T12:40:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-08T21:04:10.415162Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647"
        },
        {
          "category": "none_available",
          "date": "2026-04-21T12:40:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-6785",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "category": "description",
          "text": "Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-6785"
        }
      ],
      "release_date": "2026-04-26T19:53:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-08T21:04:10.415162Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647"
        },
        {
          "category": "none_available",
          "date": "2026-04-26T19:53:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-6752",
      "cwe": {
        "id": "CWE-131",
        "name": "Incorrect Calculation of Buffer Size"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nIncorrect boundary conditions in the WebRTC component",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-6752"
        }
      ],
      "release_date": "2026-04-21T12:40:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-08T21:04:10.415162Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647"
        },
        {
          "category": "none_available",
          "date": "2026-04-21T12:40:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-6749",
      "cwe": {
        "id": "CWE-824",
        "name": "Access of Uninitialized Pointer"
      },
      "notes": [
        {
          "category": "description",
          "text": "Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-6749"
        }
      ],
      "release_date": "2026-04-21T12:40:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-08T21:04:10.415162Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647"
        },
        {
          "category": "none_available",
          "date": "2026-04-21T12:40:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-8388",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "category": "description",
          "text": "Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-8388"
        }
      ],
      "release_date": "2026-05-12T12:36:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-08T21:04:10.415162Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647"
        },
        {
          "category": "none_available",
          "date": "2026-05-12T12:36:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-6746",
      "cwe": {
        "id": "CWE-825",
        "name": "Expired Pointer Dereference"
      },
      "notes": [
        {
          "category": "description",
          "text": "Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-6746"
        }
      ],
      "release_date": "2026-04-21T12:40:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-08T21:04:10.415162Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1780952647"
        },
        {
          "category": "none_available",
          "date": "2026-04-21T12:40:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}