{"id":"CGA-vmmq-mhxr-phh7","modified":"2026-07-17T20:13:05.002395567Z","published":"2026-07-01T10:25:14Z","withdrawn":"2026-07-17T20:13:05.002395431Z","related":["CVE-2026-0886","GHSA-7328-g372-24vf"],"affected":[{"package":{"name":"firefox","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/firefox"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.7-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-vmmq-mhxr-phh7.json"}},{"package":{"name":"firefox-esr","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/firefox-esr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.7-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-vmmq-mhxr-phh7.json"}},{"package":{"name":"firefox","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/firefox"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.7-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-vmmq-mhxr-phh7.json"}}],"schema_version":"1.7.5"}