{"id":"SUSE-SU-2026:4268-1","summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\nMozilla Thunderbird 153.2:\n\n  * fixed: Deleting an Exchange account retained the outgoing\n    server settings \n  * fixed: Thunderbird upgrade disabled Settings menu for\n    versions before macOS 13 \n  * fixed: Windows jump list menu no longer functioned correctly\n  * fixed: Security fixes MFSA 2026-88 (bsc#1278001):\n  * CVE-2026-84639 \n    Uninitialized memory in MIME parsing\n  * CVE-2026-84640 \n    One byte overflow read in mail parser\n  * CVE-2026-84641 \n    Information disclosure due to malicious IMAP server response\n  * CVE-2026-84637 \n    Calendar invitation attachments could launch local\n    executables\n  * CVE-2026-84642 \n    Allowed UNC hostnames for attachments interpreted as a\n    regular expression\n  * CVE-2026-75874 \n    Sandbox escape in the Remote Settings Client component\n  * CVE-2026-84118 \n    Use-after-free in the JavaScript: GC component\n  * CVE-2026-84119 \n    Sandbox escape due to use-after-free in the DOM: Navigation\n    component\n  * CVE-2026-84120 \n    Use-after-free in the Audio/Video component\n  * CVE-2026-84121 \n    Sandbox escape due to use-after-free in the DOM: Security\n    component\n  * CVE-2026-84122 \n    Use-after-free in the Audio/Video component\n  * CVE-2026-84123 \n    Privilege escalation due to use-after-free in the Graphics:\n    WebGPU component\n  * CVE-2026-84124 \n    Use-after-free in the DOM: Core & HTML component\n  * CVE-2026-84125 \n    Use-after-free in the DOM: Core & HTML component\n  * CVE-2026-74952 \n    Privilege escalation in the Application Update component\n  * CVE-2026-84129 \n    Site isolation issue in the DOM: Navigation component\n  * CVE-2026-84130 \n    Information disclosure in the Graphics: WebGPU component\n  * CVE-2026-84131 \n    Privilege escalation due to invalid pointer in the Graphics\n    component\n  * CVE-2026-84132 \n    Information disclosure in the Networking: HTTP component\n  * CVE-2026-84133 \n    Site isolation issue in the DOM: Push Subscriptions component\n  * CVE-2026-84134 \n    Other issue in the Profile Backup component\n  * CVE-2026-84136 \n    Other issue in the DOM: Navigation component\n  * CVE-2026-84137 \n    Spoofing issue in the DOM: Core & HTML component\n  * CVE-2026-84139 \n    Clickjacking issue in the DOM: Events component\n  * CVE-2026-84140 \n    Site isolation issue in the DOM: Navigation component\n  * CVE-2026-84141 \n    Integer overflow in the Graphics: ImageLib component\n  * CVE-2026-84143 \n    Internally found bugs fixed in Thunderbird 155, Thunderbird\n    ESR 153.2 and Thunderbird ESR 140.15\n  * CVE-2026-84144 \n    Internally found bugs fixed in Thunderbird 155 and\n    Thunderbird ESR 153.2\n  * CVE-2026-84145 \n    Internally found bugs fixed in Thunderbird 155, Thunderbird\n    ESR 153.2 and Thunderbird ESR 140.15\n\n- Mozilla Thunderbird 153.1.1\n\n  * fixed: Thunderbird upgrade disabled composition toolbar\n  * fixed: Draft was not preserved when encrypted message send\n    failed \n  * fixed: Account Hub prompted for calendar credentials after\n    successful login \n  * fixed: Thunderbird crash fixes \n  * fixed: Folder compaction showed incorrect disk space recovery\n    estimates \n  * fixed: Thunderbird failed to launch GPU process \n\n- Mozilla Thunderbird 153.1\n\n  * fixed: Autoscroll icon was missing directional arrows in\n    scrollable messages \n  * fixed: Security fixes MFSA 2026-80 (bsc#1274867):\n  * CVE-2026-74934 \n    Site isolation issue in the Graphics: CanvasWebGL component\n  * CVE-2026-74935 \n    Privilege escalation in the DOM: Networking component\n  * CVE-2026-74936 \n    Use-after-free in the JavaScript: WebAssembly component\n  * CVE-2026-74937 \n    Use-after-free in the JavaScript: GC component\n  * CVE-2026-74938 \n    Mitigation bypass in the JavaScript: GC component\n  * CVE-2026-74939 \n    Privilege escalation in the DOM: Navigation component\n  * CVE-2026-74940 \n    Use-after-free in the Graphics: Text component\n  * CVE-2026-74941 \n    Privilege escalation in the Graphics: CanvasWebGL component\n  * CVE-2026-74942 \n    Privilege escalation in the Remote Settings Client component\n  * CVE-2026-74943 \n    Use-after-free in the Graphics: ImageLib component\n  * CVE-2026-74944 \n    Use-after-free in the DOM: Core & HTML component\n  * CVE-2026-74945 \n    Information disclosure in the Graphics: Text component\n  * CVE-2026-74946 \n    Privilege escalation due to incorrect boundary conditions in\n    the Graphics: CanvasWebGL component\n  * CVE-2026-74947 \n    Privilege escalation due to invalid pointer in the Graphics\n    component\n  * CVE-2026-74948 \n    Information disclosure in the Graphics component\n  * CVE-2026-74949 \n    Privilege escalation due to use-after-free in the Graphics:\n    Canvas2D component\n  * CVE-2026-74950 \n    Privilege escalation in the Downloads API component\n  * CVE-2026-74953 \n    Privilege escalation in the Networking: Cookies component\n  * CVE-2026-74954 \n    Information disclosure due to side-channel in the Storage:\n    Cache API component\n  * CVE-2026-74955 \n    Privilege escalation in the Request Handling component\n  * CVE-2026-74956 \n    Same-origin policy bypass in the DOM: Service Workers\n    component\n  * CVE-2026-74957 \n    Mitigation bypass in the Safe Browsing component\n  * CVE-2026-74958 \n    Information disclosure in the WebRTC component\n  * CVE-2026-74959 \n    Mitigation bypass in the Storage: Cache API component\n  * CVE-2026-74960 \n    Site isolation issue in the WebExtensions component\n  * CVE-2026-74961 \n    Side-channel in the Web Audio component\n  * CVE-2026-74962 \n    Site isolation issue in the Networking: Cookies component\n  * CVE-2026-74963 \n    Same-origin policy bypass in the Networking: Cookies\n    component\n  * CVE-2026-74964 \n    Integer overflow in the Graphics component\n  * CVE-2026-74965 \n    Privilege escalation in the Shell Integration component\n  * CVE-2026-74966 \n    Information disclosure in the Form Autofill component\n  * CVE-2026-74967 \n    Same-origin policy bypass in the Audio/Video: Playback\n    component\n  * CVE-2026-74968 \n    Site isolation issue in the Graphics: WebRender component\n  * CVE-2026-74969 \n    Use-after-free in the Layout: Text and Fonts component\n  * CVE-2026-74970 \n    Site isolation issue in the Graphics component\n  * CVE-2026-74971 \n    Information disclosure in the DOM: UI Events & Focus Handling\n    component\n  * CVE-2026-74972 \n    Information disclosure in the DOM: Push Subscriptions\n    component\n  * CVE-2026-74973 \n    Race condition, use-after-free in the Graphics component\n  * CVE-2026-74974 \n    Same-origin policy bypass in the Graphics: ImageLib component\n  * CVE-2026-74976 \n    JIT miscompilation in the JavaScript Engine: JIT component\n  * CVE-2026-74977 \n    Integer overflow in the Graphics component\n  * CVE-2026-74978 \n    Clickjacking issue in the Widget component\n  * CVE-2026-74979 \n    Mitigation bypass in the Add-ons Manager component\n  * CVE-2026-74981 \n    Site isolation issue in the Audio/Video: Web Codecs component\n  * CVE-2026-74982 \n    Denial-of-service in the Widget component\n  * CVE-2026-74983 \n    Mitigation bypass in the Data Loss Prevention component\n  * CVE-2026-74984 \n    Race condition in the JavaScript Engine component\n  * CVE-2026-74985 \n    Privilege escalation in the Enterprise Policies component\n  * CVE-2026-74986 \n    Site isolation issue in the CSS Parsing and Computation\n    component\n  * CVE-2026-74987 \n    Internally found bugs fixed in Thunderbird ESR 140.14,\n    Thunderbird ESR 153.1 and Thunderbird 154\n  * CVE-2026-74988 \n    Internally found bugs fixed in Thunderbird ESR 153.1 and\n    Thunderbird 154\n  * CVE-2026-74990 \n    Internally found bugs fixed in Thunderbird ESR 140.14,\n    Thunderbird ESR 153.1 and Thunderbird 154\n\n- Mozilla Thunderbird 153.0.3\n\n  * fixed: Dragging attachments from Local Folders to the desktop\n    failed on Windows \n  * fixed: IMAP tags did not sync automatically across clients\n  * fixed: DisablePasswordReveal policy failed to prevent\n    revealing saved passwords \n  * fixed: Thunderbird could crash when saving a sent Exchange\n    message \n\n- Mozilla Thunderbird 153.0.2\n\n  * changed: Restored previous Yahoo sign-in flow to improve\n    login reliability \n  * fixed: Edit Calendar dialog opened without a window title\n  * fixed: Thunderbird could crash when going offline with active\n    IMAP connection \n\n- Mozilla Thunderbird 153.0.1\n\n  * changed: There are no Thunderbird changes requiring release\n    notes in this release\n\n- Mozilla Thunderbird 153\n\n  MFSA 2026-71 (bsc#1271649):\n  * new: Visual signatures can be added to PDF attachments opened\n    in Thunderbird \n  * new: 'Copy Message Link' and 'Copy News Link' added to header\n    pane 'More actions' \n  * new: Accessiblity is improved in various tree views\n  * new: Added 'Archive' action to mail notifications\n  * new: Add 'Show Full Path' folder pane option for compact view\n    modes \n  * new: Unified folders now display account color indicator with\n    account name tooltip \n  * new: Folder copy enabled within mail server accounts and\n    local folders \n  * new: 'Reset Folder Order' option added to folder pane to\n    reset custom folder sorting \n  * new: Add `mail.useLocalizedFolderNames' to toggle special\n    folder name localization \n  * new: 'Favorites' added as destination for 'Move To' and\n    'File' buttons \n  * new: Composer now shows a warning if user's configured\n    OpenPGP key expires soon \n  * new: Enabled configuration of preferred OpenPGP keyserver via\n    the UI \n  * new: Add `mail.openpgp.load_untested_gpgme_version` to load\n    untested GPGME version \n  * new: Added support for generating Unobtrusive Signatures\n    (OpenPGP) \n  * new: Implemented option to show only messages without any tag\n  * new: Message body search enabled for OpenPGP and S/MIME\n    encrypted messages \n  * new: SecurityDevices enabled in enterprise policies\n  * new: Enable support for DNS over HTTPS \n  * new: OAuth login for mail accounts now opens in default web\n    browser \n  * new: Thundermail services can now be used without installing\n    an add-on \n  * new: OAuth responses now verify issuer fields and reject\n    missing required issuers \n  * new: Enable the 'Sign in with Thundermail' button in Account\n    Hub \n  * new: Account hub is opened on the first run of Thunderbird\n  * new: Account Hub email manual config option added\n  * new: Enable Thundermail OAuth sign-in with account auto-\n    configuration \n  * new: Address book cards can be copied to the clipboard as\n    vCard \n  * new: Enable exporting selected address book cards \n  * new: Custom Accent Color can be chosen in Appearance Settings\n  * new: Enable support for Microsoft Exchange via Exchange Web\n    Services \n  * new: Calendar month/multiweek views are now scrollable with\n    touch screen \n  * new: Tasks can be sorted by created or modified date\n  * new: PDF pages can be reorganized directly in the PDF viewer\n  * changed: 'Copy Message Location' removed from mail context\n    menu \n  * changed: Read folders are now removed from Unread Folders\n    view \n  * changed: Special folders are now localized based on a\n    restricted set of names \n  * changed: OpenPGP public key no longer attached by default in\n    signed-only messages \n  * changed: Address books are now created in Account Hub\n  * changed: Yahoo, AT&T, AOL accounts migrated to OAuth 2.0 with\n    PKCE for improved security \n  * changed: GMail OAuth updated to use PKCE \n  * changed: Skype has been retired and therefore dropped from\n    Address book IM selection \n  * changed: Removed pref `default_supports_diskspace.{HOST}`\n  * changed: Removed pref `default_offline_support_level.{HOST}`\n  * changed: Removed Odnoklassniki chat setup and directed users\n    to XMPP configuration \n  * changed: Use of the string 'Junk' has been replaced with\n    'Spam' \n  * changed: Updated about:rights to replace local with hosted\n    url \n  * changed: Stop shipping 32-bit Linux x86 binaries\n  * changed: 'Hide completed tasks' now also hides cancelled\n    tasks \n  * changed: Stop shipping 32-bit Linux x86 binaries\n  * fixed: Thunderbird could crash when parsing message state\n  * fixed: The English string for the Angry emoji was incorrectly\n    named as the Yell emoji \n  * fixed: Notification sounds did not respect operating system's\n    do-not-disturb mode \n  * fixed: Non-English localized Thunderbird created English\n    special folders on first start \n  * fixed: Copying text from some error alerts was not possible\n  * fixed: Fastmail CalDAV app password access failed due to\n    forced OAuth regression \n  * fixed: Thunderbird could crash in server subscription logic\n  * fixed: Could not distinguish folders with same name in\n    'Recent Destinations' and 'Favorites' \n  * fixed: Donation banner stole focus when Thunderbird was\n    running in the background \n  * fixed: Unknown command-line arguments passed to Thunderbird\n    did not print warning \n  * fixed: Thunderbird could crash when processing new incoming\n    messages \n  * fixed: Spam messages triggered new mail notifications before\n    being moved to Spam folder \n  * fixed: Web pages with bad certificates displayed as blank\n  * fixed: Memory leak after opening New Window from folder pane\n    context menu \n  * fixed: Importing a vCard only displayed VCF files in the file\n    picker \n  * fixed: Calendar view tabs were not properly keyboard\n    accessible \n  * fixed: Ctrl+S did not save PDF attachments opened in\n    Thunderbird tabs \n  * fixed: TLS errors incorrectly reported all unknown failures\n    as untrusted certificates \n  * fixed: Thunderbird could crash when copying an empty list of\n    messages \n  * fixed: Incorrect roaming data directory caused regression on\n    Windows and macOS \n  * fixed: Changing to new drafts folder and then back did not\n    correctly restore the folder \n  * fixed: Message headers were re-downloaded at every startup\n  * fixed: Old IMAP profile migration deleted INBOX and other\n    mailbox files \n  * fixed: 'Search Messages...' dialog could not be opened\n    outside the email tab \n  * fixed: Option did not exist to create new address book under\n    File -\u003e New \n  * fixed: Newly created folder was missing under 'Recent' when\n    moving a message \n  * fixed: Could not compose new message if the folder pane was\n    empty \n  * fixed: 'Delete' was missing from context menu when multiple\n    IMAP folders were selected \n  * fixed: Compacting multiple folders failed and did not compact\n  * fixed: Shift-click for 'Edit' button in drafts header view\n    did not work \n  * fixed: 'Replace All' in Compose did not update plain text\n    until dialog closed \n  * fixed: Status bar messages displayed unlocalized folder names\n    or IMAP mailbox names \n  * fixed: Saved email filenames were not not always cross-\n    platform safe \n  * fixed: Space bar did not scroll in PDF attachments opened\n    from emails \n  * fixed: Folder location widget used non-localised name\n  * fixed: Empty confirmation dialog when more messages opened in\n    tabs than `mailnews.open_tab_warning` \n  * fixed: Removing tags from IMAP messages could fail and tags\n    reappeared after refresh \n  * fixed: Toggling dark message mode did not restore focus and\n    scroll position \n  * fixed: 'Show remote content' did not display remote content\n    for EML message \n  * fixed: Emoji sequences were not properly handled in subject\n    lines \n  * fixed: 'Delete' button in unified toolbar could delete\n    attachments instead of message \n  * fixed: 'Repair text encoding' could duplicate recipient and\n    attachments \n  * fixed: Some IMAP emails showed current time instead of\n    correct received date \n  * fixed: Deleting a single message in folder using 'Group by\n    Sort' failed after CTRL+A \n  * fixed: New newsgroups were not added in alphabetical order by\n    default \n  * fixed: Sorting by threads only brought threads with unread\n    top messages to the top \n  * fixed: News message marked read after NNTP error prevented\n    retrieval from server \n  * fixed: 'Recent destinations' submenu was not sorted by time\n    of modification \n  * fixed: Account column could display incorrect account name\n  * fixed: 'Tag' submenu of mail context menu could be populated\n    incorrectly \n  * fixed: Unified archive subfolders could show wrong names and\n    no messages \n  * fixed: Moving saved search/virtual folder under IMAP could\n    fail \n  * fixed: New Folder dialog allowed invalid folder creation\n    without a selected parent folder \n  * fixed: New/unread messages in collapsed thread were not\n    obvious enough \n  * fixed: Pressing Delete on Trash folder could remove it\n    without confirmation \n  * fixed: Renaming of a 'unified folder' created a duplicate\n  * fixed: Clicking on a folder in the folder pane did not always\n    open folder \n  * fixed: Messages nested deeper than 255 levels disappeared\n    from threading view \n  * fixed: Performing Delete followed by Undo on thread parent\n    message could corrupt view \n  * fixed: Single messages still appeared collapsible after\n    thread members were deleted \n  * fixed: Updated threads remained misordered until folder\n    refresh or resort \n  * fixed: Global search failed to display inaccessible messages\n    found in local folders \n  * fixed: Numeric subfolders were sorted alphabetically instead\n    of naturally \n  * fixed: Virtual folder folder-picker showed unlabeled IM\n    account as selectable folder \n  * fixed: Some folders showed new mail count prior to receiving\n    mail \n  * fixed: Menu Bar -\u003e View contained duplicate accelerator keys\n  * fixed: Unified toolbar Spam button did not switch to 'Not\n    Spam' when spam message selected \n  * fixed: Warning was not logged if\n    `mail.openpgp.alias_rules_file` file did not exist\n  * fixed: Not all headers were signed when creating digitally\n    signed OpenPGP email \n  * fixed: When configuring external GnuPG, user was not promted\n    to import public key \n  * fixed: 'Open and Show' for OpenPGP-signed message (.eml) did\n    not work \n  * fixed: Invalidly signed unencrypted emails were indicated as\n    worse than unsigned ones \n  * fixed: Reason for revoked certificate was not shown\n  * fixed: Apple Mail OpenPGP emails failed to decrypt due to\n    hidden recipient key ID \n  * fixed: OpenPGP import of public key with experimental packets\n    failed with unclear error \n  * fixed: Opening messages with OpenPGP keys was slow and\n    blocked the UI for large keyrings \n  * fixed: OpenPGP key refresh failed when fingerprint lookup\n    returned multiple results \n  * fixed: Encrypted Gmail CSE emails with outer opaque S/MIME\n    were not readable \n  * fixed: Invalid S/MIME encryption certificate caused\n    misleading send errors \n  * fixed: 'Search Messages' search did not finish due to\n    unparsable local folders \n  * fixed: Search results showed older irrelevant emails before\n    newer exact matches \n  * fixed: Filter search on Body missed draft messages containing\n    German umlauts \n  * fixed: Esc cleared quick filter pin after changing folder\n  * fixed: Thunderbird could crash during local message search\n  * fixed: Replying could fail with\n    `mailnews.reply_quoting_selection.multi_word` set false\n  * fixed: Drag-drop of unselected contact inserted wrong or no\n    email address \n  * fixed: Changing identity in compose window caused modified\n    draft not to be saved \n  * fixed: Shift-click 'Compose Message To' on 'mailto' link did\n    not open in plain text \n  * fixed: Reply with selected text lost formatting for HTML\n    messages containing &lt;/pre&gt; \n  * fixed: Multipart/related attachments were not preserved when\n    editing or forwarding \n  * fixed: Forwarded malformed MIME email had empty body and\n    extra attachment \n  * fixed: Message compose window was removed from Task Bar after\n    saving as draft or template \n  * fixed: Dragging email address between compose windows failed\n    to add recipients \n  * fixed: Thunderbird could crash when using Find and Replace\n    All \n  * fixed: Compose with PDF attachments opened PDFs instead of\n    creating a new email \n  * fixed: Multiple saves while using 'Options' -\u003e 'Send a Copy'\n    resulted in multiple copies \n  * fixed: Search for 'Attachment' in Settings menu did not find\n    'Files and Attachments' \n  * fixed: Add-on account creation did not work with Account Hub\n  * fixed: Owl install did not show link to website in Account\n    Hub \n  * fixed: Username field did not appear in Account Hub when\n    exchange authentication failed \n  * fixed: Account Hub advanced config setup did not include\n    default outgoing config \n  * fixed: Disabled inputs could be toggled in Account Hub\n    address book \n  * fixed: Users could not disable spinning overlay in Account\n    Hub for email \n  * fixed: Account Hub local address book creation could continue\n    with blank name \n  * fixed: Account Hub email success messages were not always\n    accurate about config source \n  * fixed: Calendar/address book sections were shown in Account\n    Hub when there were none \n  * fixed: New password-based Exchange accounts failed to save\n    passwords in login manager \n  * fixed: Account hub showed connection security instead of\n    actual authentication method \n  * fixed: New identity dialog lacked reply-matching and end-to-\n    end encryption settings \n  * fixed: Thunderbird could fail to shut down cleanly during\n    active OAuth requests \n  * fixed: Account Hub kept OAuth selected after changing to\n    hostname without OAuth support \n  * fixed: Account Hub autodetect wrongly prompted for a password\n    when auth was unavailable \n  * fixed: Interrupted external OAuth2 setup required restarting\n    Thunderbird \n  * fixed: The default account could be reset after restart if\n    uninitialized \n  * fixed: Virtual folders did not update correctly for filtered\n    POP3 messages \n  * fixed: 'Copy Message to' action in a newsgroup filter did not\n    work \n  * fixed: Thunderbird could crash while importing mail thread\n  * fixed: Thunderbird did not clearly fail when importing\n    profile from a bad source \n  * fixed: Thunderbird could not import profile located at the\n    top level of zip file \n  * fixed: 'Any Number' was unavailable in address book search\n    with 'Match all of the following' \n  * fixed: Contact not found in Advanced Address Book Search if\n    phone number had a period \n  * fixed: Thunderbird did not display contact photos in WebP\n    format from CardDAV servers \n  * fixed: Opening a vCard (.vcf) from file manager or CLI did\n    not work in some cases \n  * fixed: Redirected CardDAV URLs resolved relative URLs against\n    the wrong host \n  * fixed: Installations from Microsoft Store did not open when\n    clicking 'mailto:' links \n  * fixed: Windows new message notification click did not bring\n    Thunderbird to foreground \n  * fixed: Microsoft Store installs did not open when clicking\n    'news://' link or .eml file \n  * fixed: Using thunderbird -compose with double quotes made\n    last email address invalid \n  * fixed: Clicking the backspace icon in the quick filter field\n    cleared the input field \n  * fixed: Subfolder kept stale accessibility unread count after\n    unread messages were deleted \n  * fixed: Moving virtual folder within maildir based IMAP or\n    local folder could fail \n  * fixed: Thunderbird could crash when completing folder\n    copy/move \n  * fixed: 'Edit as New Message' and inline 'Forward' not\n    possible with PGP-signed messages \n  * fixed: Various MIME improvements \n  * fixed: Forwarding some Apple Mail messages incorrectly\n    attached inline text as a file \n  * fixed: Thunderbird could crash when marking all messages as\n    read \n  * fixed: Auto-compaction could corrupt database and cause\n    crashes during syncs \n  * fixed: 'news:' URIs without specific server had incorrect\n    format displayed in status bar \n  * fixed: 'Mark' -\u003e 'All Read' affected newsgroup messages that\n    had not been fetched yet \n  * fixed: Thunderbird could not reconnect to newsgroups after\n    connection loss until restarted \n  * fixed: Sending a newsgroup post appeared successful when it\n    had actually failed \n  * fixed: Saving a new draft retained superceded version\n  * fixed: Thunderbird hung when auto-checking multiple accounts\n    for new messages \n  * fixed: Spam not checked with\n    `mail.server.default.check_all_folders_for_new` on\n  * fixed: Startup could be slow with large number of folders not\n    using subscriptions \n  * fixed: Saved search in unified folder resulted in server\n    error \n  * fixed: Thunderbird did not report refused POP3 connection\n  * fixed: Remove message body retention policy was not\n    functional \n  * fixed: POP3 could stop downloading mail until restart\n  * fixed: With auto-mark-read disabled, large mail still marked\n    as read during load delay \n  * fixed: IMAP 'Show only subscribed folders' could not be\n    changed without restart \n  * fixed: POP3 deadlocked when server went silent without\n    closing socket \n  * fixed: Thunderbird could crash when mail folder was renamed\n    or moved \n  * fixed: NNTP server with invalid TLS certificate could not be\n    added to certificate exceptions \n  * fixed: Cancelled message send could not be retried and hung\n    with SMTP timeout errors \n  * fixed: Corrupted NNTP account data caused excessive memory\n    use and startup crash \n  * fixed: Multiple selected IMAP folders could not be moved or\n    deleted together \n  * fixed: Non-Latin IMAP keywords were lowercased and encoded\n    incorrectly as MUTF-7 \n  * fixed: Message tags were lost when moving folder from local\n    folder to IMAP folder \n  * fixed: Removing a chat account threw an exception and failed\n    to clear the UI \n  * fixed: Enterprise policy use not indicated in\n    about:preferences with link to about:policies \n  * fixed: Language field in settings was empty after restart in\n    Troubleshoot Mode \n  * fixed: Primary Password policy was detected but not enforced\n    for saved account passwords \n  * fixed: Archived RSS feed messages were sent to the archive\n    folder of default identity \n  * fixed: Broken feed icon could prevent updating of feeds\n  * fixed: Task reminders could fail for tasks without end dates\n    or with shifted due dates \n  * fixed: Calendar did not alert user for connection issues\n  * fixed: Copying one recurring event occurrence failed to set\n    the date when pasted \n  * fixed: Could not copy an event in multiweek or month view by\n    drag-and-drop \n  * fixed: Duplicate attendees were added to invitations instead\n    of being filtered out \n  * fixed: Calendar discovery with certificate error displayed\n    multiple exceptions \n  * fixed: It was not possible to create date-only all-day tasks\n  * fixed: Task percentage complete was not preserved separately\n    from status in tooltips \n  * fixed: Calendar invites were incorrectly marked processed\n    after calendar sync completed \n  * fixed: ICS event comments were not displayed in Thunderbird\n    event details \n  * fixed: Dismissed Gmail calendar reminder did nothing and item\n    stayed visible \n  * fixed: iCal imports misread unknown timezones as GMT,\n    creating events at wrong times \n  * fixed: Could not export local calendar as HTML \n  * fixed: Cancelled filter edit dialog closed the message filter\n    dialog \n  * fixed: Visual and UX improvements \n  * CVE-2026-14899 \n    Off-by-one out of bounds read in MIME header parser for\n    forwarding\n  * CVE-2026-16349 \n    Same-origin policy bypass in the DOM: Navigation component\n  * CVE-2026-16350 \n    Incorrect boundary conditions in the Audio/Video: cubeb\n    component\n  * CVE-2026-16362 \n    Use-after-free in the WebRTC: Audio/Video component\n  * CVE-2026-16351 \n    Sandbox escape due to use-after-free in the DOM: Navigation\n    component\n  * CVE-2026-16352 \n    Sandbox escape due to use-after-free in the Disability Access\n    APIs component\n  * CVE-2026-16363 \n    JIT miscompilation in the JavaScript: WebAssembly component\n  * CVE-2026-16364 \n    Incorrect boundary conditions in the Audio/Video: Playback\n    component\n  * CVE-2026-16365 \n    Privilege escalation in the DOM: Workers component\n  * CVE-2026-16366 \n    Privilege escalation in the DOM: Navigation component\n  * CVE-2026-16353 \n    Invalid pointer in the DOM: Bindings (WebIDL) component\n  * CVE-2026-16354 \n    Information disclosure in the Graphics: ImageLib component\n  * CVE-2026-16367 \n    Sandbox escape due to invalid pointer in the Disability\n    Access APIs component\n  * CVE-2026-16368 \n    Incorrect boundary conditions in the JavaScript: WebAssembly\n    component\n  * CVE-2026-16369 \n    Integer overflow in the JavaScript: WebAssembly component\n  * CVE-2026-16355 \n    JIT miscompilation in the JavaScript Engine: JIT component\n  * CVE-2026-16356 \n    Sandbox escape due to use-after-free in the Disability Access\n    APIs component\n  * CVE-2026-16357 \n    Incorrect boundary conditions in the Graphics component\n  * CVE-2026-16370 \n    Mitigation bypass in the DOM: Networking component\n  * CVE-2026-16371 \n    Privilege escalation in the DOM: Navigation component\n  * CVE-2026-16372 \n    Privilege escalation in the DOM: Content Processes component\n  * CVE-2026-16374 \n    Information disclosure in the Framework component in DevTools\n  * CVE-2026-16375 \n    Site isolation issue in the Networking: HTTP component\n  * CVE-2026-16376 \n    Denial-of-service in the Graphics: WebGPU component\n  * CVE-2026-16377 \n    Mitigation bypass in the PDF Viewer component\n  * CVE-2026-16378 \n    Other issue in the DOM: Copy & Paste and Drag & Drop\n    component\n  * CVE-2026-16379 \n    Privilege escalation in the DOM: Content Processes component\n  * CVE-2026-16358 \n    Site isolation issue in the Graphics: WebRender component\n  * CVE-2026-16380 \n    Mitigation bypass in the Networking component\n  * CVE-2026-16381 \n    Same-origin policy bypass in the Networking: DNS component\n  * CVE-2026-16382 \n    Mitigation bypass in the DOM: Service Workers component\n  * CVE-2026-16383 \n    Mitigation bypass in the DOM: Networking component\n  * CVE-2026-16384 \n    Information disclosure due to uninitialized memory in the\n    Graphics: WebGPU component\n  * CVE-2026-16385 \n    Information disclosure due to uninitialized memory in the\n    Graphics: WebGPU component\n  * CVE-2026-16386 \n    Information disclosure due to uninitialized memory in the\n    Graphics: WebGPU component\n  * CVE-2026-16387 \n    Site isolation issue in the Networking component\n  * CVE-2026-16388 \n    Sandbox escape in the DOM: Networking component\n  * CVE-2026-16389 \n    Incorrect boundary conditions, integer overflow in the\n    Libraries component in NSS\n  * CVE-2026-16390 \n    Mitigation bypass in the Enterprise Policies component\n  * CVE-2026-16391 \n    Information disclosure in the Storage: IndexedDB component\n  * CVE-2026-16392 \n    JIT miscompilation in the JavaScript Engine: JIT component\n  * CVE-2026-16393 \n    Incorrect boundary conditions in the Graphics: WebGPU\n    component\n  * CVE-2026-16359 \n    Incorrect boundary conditions in the Audio/Video: GMP\n    component\n  * CVE-2026-16394 \n    Mitigation bypass in the DOM: Security component\n  * CVE-2026-16395 \n    Integer overflow in the Audio/Video component\n  * CVE-2026-16396 \n    Privilege escalation in WebExtensions\n  * CVE-2026-16398 \n    Site isolation issue in the Graphics component\n  * CVE-2026-16399 \n    Site isolation issue in the DOM: Navigation component\n  * CVE-2026-16400 \n    Information disclosure in the DOM: Security component\n  * CVE-2026-16401 \n    Privilege escalation in the Data Loss Prevention component\n  * CVE-2026-16402 \n    Integer overflow in the Graphics: ImageLib component\n  * CVE-2026-16403 \n    Spoofing issue in the Address Bar component\n  * CVE-2026-16405 \n    Information disclosure in the Networking: WebSockets\n    component\n  * CVE-2026-16406 \n    Mitigation bypass in the Networking component\n  * CVE-2026-16407 \n    Mitigation bypass in the DOM: Service Workers component\n  * CVE-2026-16408 \n    Integer overflow in the Audio/Video: Playback component\n  * CVE-2026-16409 \n    Invalid pointer in the Security: PSM component\n  * CVE-2026-16410 \n    JIT miscompilation in the JavaScript Engine: JIT component\n  * CVE-2026-16411 \n    Memory safety bugs fixed in Thunderbird 153\n  * CVE-2026-16412 \n    Memory safety bugs fixed in Thunderbird ESR 140.13 and\n    Thunderbird 153\n  * CVE-2026-16360 \n    Memory safety bugs fixed in Thunderbird ESR 140.13 and\n    Thunderbird 153\n","modified":"2026-09-19T09:00:03.901982656Z","published":"2026-09-18T14:51:02Z","related":["CVE-2024-34703","CVE-2026-14899","CVE-2026-16349","CVE-2026-16350","CVE-2026-16351","CVE-2026-16352","CVE-2026-16353","CVE-2026-16354","CVE-2026-16355","CVE-2026-16356","CVE-2026-16357","CVE-2026-16358","CVE-2026-16359","CVE-2026-16360","CVE-2026-16362","CVE-2026-16363","CVE-2026-16364","CVE-2026-16365","CVE-2026-16366","CVE-2026-16367","CVE-2026-16368","CVE-2026-16369","CVE-2026-16370","CVE-2026-16371","CVE-2026-16372","CVE-2026-16374","CVE-2026-16375","CVE-2026-16376","CVE-2026-16377","CVE-2026-16378","CVE-2026-16379","CVE-2026-16380","CVE-2026-16381","CVE-2026-16382","CVE-2026-16383","CVE-2026-16384","CVE-2026-16385","CVE-2026-16386","CVE-2026-16387","CVE-2026-16388","CVE-2026-16389","CVE-2026-16390","CVE-2026-16391","CVE-2026-16392","CVE-2026-16393","CVE-2026-16394","CVE-2026-16395","CVE-2026-16396","CVE-2026-16398","CVE-2026-16399","CVE-2026-16400","CVE-2026-16401","CVE-2026-16402","CVE-2026-16403","CVE-2026-16405","CVE-2026-16406","CVE-2026-16407","CVE-2026-16408","CVE-2026-16409","CVE-2026-16410","CVE-2026-16411","CVE-2026-16412","CVE-2026-74934","CVE-2026-74935","CVE-2026-74936","CVE-2026-74937","CVE-2026-74938","CVE-2026-74939","CVE-2026-74940","CVE-2026-74941","CVE-2026-74942","CVE-2026-74943","CVE-2026-74944","CVE-2026-74945","CVE-2026-74946","CVE-2026-74947","CVE-2026-74948","CVE-2026-74949","CVE-2026-74950","CVE-2026-74952","CVE-2026-74953","CVE-2026-74954","CVE-2026-74955","CVE-2026-74956","CVE-2026-74957","CVE-2026-74958","CVE-2026-74959","CVE-2026-74960","CVE-2026-74961","CVE-2026-74962","CVE-2026-74963","CVE-2026-74964","CVE-2026-74965","CVE-2026-74966","CVE-2026-74967","CVE-2026-74968","CVE-2026-74969","CVE-2026-74970","CVE-2026-74971","CVE-2026-74972","CVE-2026-74973","CVE-2026-74974","CVE-2026-74976","CVE-2026-74977","CVE-2026-74978","CVE-2026-74979","CVE-2026-74981","CVE-2026-74982","CVE-2026-74983","CVE-2026-74984","CVE-2026-74985","CVE-2026-74986","CVE-2026-74987","CVE-2026-74988","CVE-2026-74990","CVE-2026-75874","CVE-2026-84118","CVE-2026-84119","CVE-2026-84120","CVE-2026-84121","CVE-2026-84122","CVE-2026-84123","CVE-2026-84124","CVE-2026-84125","CVE-2026-84129","CVE-2026-84130","CVE-2026-84131","CVE-2026-84132","CVE-2026-84133","CVE-2026-84134","CVE-2026-84136","CVE-2026-84137","CVE-2026-84139","CVE-2026-84140","CVE-2026-84141","CVE-2026-84143","CVE-2026-84144","CVE-2026-84145","CVE-2026-84637","CVE-2026-84639","CVE-2026-84640","CVE-2026-84641","CVE-2026-84642"],"upstream":["CVE-2024-34703","CVE-2026-14899","CVE-2026-16349","CVE-2026-16350","CVE-2026-16351","CVE-2026-16352","CVE-2026-16353","CVE-2026-16354","CVE-2026-16355","CVE-2026-16356","CVE-2026-16357","CVE-2026-16358","CVE-2026-16359","CVE-2026-16360","CVE-2026-16362","CVE-2026-16363","CVE-2026-16364","CVE-2026-16365","CVE-2026-16366","CVE-2026-16367","CVE-2026-16368","CVE-2026-16369","CVE-2026-16370","CVE-2026-16371","CVE-2026-16372","CVE-2026-16374","CVE-2026-16375","CVE-2026-16376","CVE-2026-16377","CVE-2026-16378","CVE-2026-16379","CVE-2026-16380","CVE-2026-16381","CVE-2026-16382","CVE-2026-16383","CVE-2026-16384","CVE-2026-16385","CVE-2026-16386","CVE-2026-16387","CVE-2026-16388","CVE-2026-16389","CVE-2026-16390","CVE-2026-16391","CVE-2026-16392","CVE-2026-16393","CVE-2026-16394","CVE-2026-16395","CVE-2026-16396","CVE-2026-16398","CVE-2026-16399","CVE-2026-16400","CVE-2026-16401","CVE-2026-16402","CVE-2026-16403","CVE-2026-16405","CVE-2026-16406","CVE-2026-16407","CVE-2026-16408","CVE-2026-16409","CVE-2026-16410","CVE-2026-16411","CVE-2026-16412","CVE-2026-74934","CVE-2026-74935","CVE-2026-74936","CVE-2026-74937","CVE-2026-74938","CVE-2026-74939","CVE-2026-74940","CVE-2026-74941","CVE-2026-74942","CVE-2026-74943","CVE-2026-74944","CVE-2026-74945","CVE-2026-74946","CVE-2026-74947","CVE-2026-74948","CVE-2026-74949","CVE-2026-74950","CVE-2026-74952","CVE-2026-74953","CVE-2026-74954","CVE-2026-74955","CVE-2026-74956","CVE-2026-74957","CVE-2026-74958","CVE-2026-74959","CVE-2026-74960","CVE-2026-74961","CVE-2026-74962","CVE-2026-74963","CVE-2026-74964","CVE-2026-74965","CVE-2026-74966","CVE-2026-74967","CVE-2026-74968","CVE-2026-74969","CVE-2026-74970","CVE-2026-74971","CVE-2026-74972","CVE-2026-74973","CVE-2026-74974","CVE-2026-74976","CVE-2026-74977","CVE-2026-74978","CVE-2026-74979","CVE-2026-74981","CVE-2026-74982","CVE-2026-74983","CVE-2026-74984","CVE-2026-74985","CVE-2026-74986","CVE-2026-74987","CVE-2026-74988","CVE-2026-74990","CVE-2026-75874","CVE-2026-84118","CVE-2026-84119","CVE-2026-84120","CVE-2026-84121","CVE-2026-84122","CVE-2026-84123","CVE-2026-84124","CVE-2026-84125","CVE-2026-84129","CVE-2026-84130","CVE-2026-84131","CVE-2026-84132","CVE-2026-84133","CVE-2026-84134","CVE-2026-84136","CVE-2026-84137","CVE-2026-84139","CVE-2026-84140","CVE-2026-84141","CVE-2026-84143","CVE-2026-84144","CVE-2026-84145","CVE-2026-84637","CVE-2026-84639","CVE-2026-84640","CVE-2026-84641","CVE-2026-84642"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264268-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271649"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274867"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278001"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-34703"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14899"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16349"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16350"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16351"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16352"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16353"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16354"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16355"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16356"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16357"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16358"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16359"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16360"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16362"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16363"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16364"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16365"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16366"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16367"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16368"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16369"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16370"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16371"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16372"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16374"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16376"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16377"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16378"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16379"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16380"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16381"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16382"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16383"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16384"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16385"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16386"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16387"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16388"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16389"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16390"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16391"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16392"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16393"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16394"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16395"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16396"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16398"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16399"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16400"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16401"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16402"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16403"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16405"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16406"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16407"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16409"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16410"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16411"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16412"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74934"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74935"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74936"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74937"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74938"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74939"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74940"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74941"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74942"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74943"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74944"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74945"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74946"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74947"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74948"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74949"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74950"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74952"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74953"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74954"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74955"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74956"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74957"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74959"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74960"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74961"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74962"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74963"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74964"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74965"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74966"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74967"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74968"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74969"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74970"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74971"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74972"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74973"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74974"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74976"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74977"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74978"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74979"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74981"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74982"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74983"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74984"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74985"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74987"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74988"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74990"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-75874"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84118"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84119"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84120"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84121"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84122"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84123"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84124"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84125"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84129"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84130"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84131"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84132"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84133"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84134"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84136"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84137"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84139"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84140"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84141"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84143"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84144"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84145"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84637"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84639"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84640"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84641"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84642"}],"affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.2.0-150400.13.3.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-other":"153.2.0-150400.13.3.1","MozillaThunderbird":"153.2.0-150400.13.3.1","MozillaThunderbird-translations-common":"153.2.0-150400.13.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4268-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP7","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.2.0-150400.13.3.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird":"153.2.0-150400.13.3.1","MozillaThunderbird-translations-common":"153.2.0-150400.13.3.1","MozillaThunderbird-translations-other":"153.2.0-150400.13.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4268-1.json"}}],"schema_version":"1.9.0"}