{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2026-12299: WebIDL [Pure] over-optimization on getter/function calls;\n  remove [Pure] annotation from blockedNodesByClassifier, getAttributeNames,\n  flex/grid container reflection, innerText/outerText, HTMLInputElement.height,\n  and MozEditableElement.editor accessors (Bug 2043139)\n- CVE-2026-12311: Linux sandbox broker did not enforce path-count per\n  operation, allowing a malicious child to send an extra path; add\n  OperationPaths() guard and preserve FORCE_DENY/CRASH_INSTEAD bits when\n  intersecting both paths' permissions (Bug 2040177)\n- CVE-2026-12328: rollup of 11 mozilla-esr115 memory-safety fixes shipped\n  as FIREFOX_115_37_0esr_RELEASE - a11y BindChildDoc cross-PBrowser guard\n  (Bug 2038477), DOM bindings ObservableArray proxy cleanup on finalize\n  (Bug 2042268), reject remote print in RecvCloneDocumentTreeInto\n  (Bug 2042929), WebRender RefPtr lifetime for previousTexture\n  (Bug 2042451), ANGLE redeclared built-in type checks (Bug 2039726),\n  ParserAtom allocate length guard (Bug 2042858), VideoBridgeParent\n  UnregisterSingleton split (Bug 2042965), ffmpeg ImageBufferTracker\n  refcounted (Bug 2041373), IndexedDB deserialization done-flag wait loop\n  (Bug 2043213), WebGL maxColorDrawBuffers clamp (Bug 2042782), and ANGLE\n  gl_SecondaryFragColorEXT rewrite (Bug 2029402)",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/almalinux9.2esu/advisories/2026/clsa-2026_1782210649.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-06-23T10:32:50Z",
      "generator": {
        "date": "2026-06-23T10:32:50Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1782210649",
      "initial_release_date": "2026-06-23T10:32:50Z",
      "revision_history": [
        {
          "date": "2026-06-23T10:32:50Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "thunderbird: Fix of 9 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "AlmaLinux 9.2",
                "product": {
                  "name": "AlmaLinux 9.2",
                  "product_id": "AlmaLinux-9.2",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:almalinux:almalinux:9.2:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "AlmaLinux"
          }
        ],
        "category": "vendor",
        "name": "AlmaLinux OS Foundation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64",
                "product": {
                  "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64",
                  "product_id": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/thunderbird@115.4.1-1.el9_2.alma.tuxcare.els13?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
                "product": {
                  "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
                  "product_id": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/thunderbird@115.4.1-1.el9_2.alma.tuxcare.els7?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
                "product": {
                  "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
                  "product_id": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/thunderbird@115.4.1-1.el9_2.alma.tuxcare.els10?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64",
                "product": {
                  "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64",
                  "product_id": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/thunderbird@115.4.1-1.el9_2.alma.tuxcare.els9?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
                "product": {
                  "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
                  "product_id": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/thunderbird@115.4.1-1.el9_2.alma.tuxcare.els4?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
                "product": {
                  "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
                  "product_id": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/thunderbird@115.4.1-1.el9_2.alma.tuxcare.els3?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
                "product": {
                  "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
                  "product_id": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/thunderbird@115.4.1-1.el9_2.alma.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
        },
        "product_reference": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64"
        },
        "product_reference": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64"
        },
        "product_reference": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        },
        "product_reference": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64"
        },
        "product_reference": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64"
        },
        "product_reference": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64"
        },
        "product_reference": "thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-12328",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-12328"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2029402%2C2038477%2C2039726%2C2041373%2C2042268%2C2042451%2C2042782%2C2042858%2C2042929%2C2042965%2C2043213",
          "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2029402%2C2038477%2C2039726%2C2041373%2C2042268%2C2042451%2C2042782%2C2042858%2C2042929%2C2042965%2C2043213"
        },
        {
          "category": "external",
          "summary": "https://www.mozilla.org/security/advisories/mfsa2026-57/",
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-57/"
        },
        {
          "category": "external",
          "summary": "https://www.mozilla.org/security/advisories/mfsa2026-58/",
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-58/"
        },
        {
          "category": "external",
          "summary": "https://www.mozilla.org/security/advisories/mfsa2026-59/",
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-59/"
        },
        {
          "category": "external",
          "summary": "https://www.mozilla.org/security/advisories/mfsa2026-60/",
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-60/"
        },
        {
          "category": "external",
          "summary": "https://www.mozilla.org/security/advisories/mfsa2026-61/",
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-61/"
        }
      ],
      "release_date": "2026-06-16T13:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-23T10:30:52.854405Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649"
        },
        {
          "category": "none_available",
          "date": "2026-06-16T13:16:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2026-8947",
      "cwe": {
        "id": "CWE-825",
        "name": "Expired Pointer Dereference"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:\nUse-after-free in the DOM: Bindings (WebIDL) component",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-8947"
        }
      ],
      "release_date": "2026-05-19T14:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-23T10:30:52.854405Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649"
        },
        {
          "category": "none_available",
          "date": "2026-05-19T14:16:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-8956",
      "cwe": {
        "id": "CWE-190",
        "name": "Integer Overflow or Wraparound"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:\nInteger overflow in the Networking: JAR component",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-8956"
        }
      ],
      "release_date": "2026-05-19T14:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-23T10:30:52.854405Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649"
        },
        {
          "category": "none_available",
          "date": "2026-05-19T14:16:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-8950",
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:\nSame-origin policy bypass in the Networking: HTTP component",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-8950"
        }
      ],
      "release_date": "2026-05-19T14:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-23T10:30:52.854405Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649"
        },
        {
          "category": "none_available",
          "date": "2026-05-19T14:16:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-12299",
      "cwe": {
        "id": "CWE-843",
        "name": "Access of Resource Using Incompatible Type ('Type Confusion')"
      },
      "notes": [
        {
          "category": "description",
          "text": "JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-12299"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.mozilla.org/show_bug.cgi?id=2043139",
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2043139"
        },
        {
          "category": "external",
          "summary": "https://www.mozilla.org/security/advisories/mfsa2026-57/",
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-57/"
        },
        {
          "category": "external",
          "summary": "https://www.mozilla.org/security/advisories/mfsa2026-58/",
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-58/"
        },
        {
          "category": "external",
          "summary": "https://www.mozilla.org/security/advisories/mfsa2026-59/",
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-59/"
        },
        {
          "category": "external",
          "summary": "https://www.mozilla.org/security/advisories/mfsa2026-60/",
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-60/"
        },
        {
          "category": "external",
          "summary": "https://www.mozilla.org/security/advisories/mfsa2026-61/",
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-61/"
        }
      ],
      "release_date": "2026-06-16T13:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-23T10:30:52.854405Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649"
        },
        {
          "category": "none_available",
          "date": "2026-06-16T13:16:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2026-8955",
      "cwe": {
        "id": "CWE-266",
        "name": "Incorrect Privilege Assignment"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:\nPrivilege escalation in the DOM: Workers component",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-8955"
        }
      ],
      "release_date": "2026-05-19T14:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-23T10:30:52.854405Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649"
        },
        {
          "category": "none_available",
          "date": "2026-05-19T14:16:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-8957",
      "cwe": {
        "id": "CWE-266",
        "name": "Incorrect Privilege Assignment"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:\nPrivilege escalation in the Enterprise Policies component",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-8957"
        }
      ],
      "release_date": "2026-05-19T14:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-23T10:30:52.854405Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649"
        },
        {
          "category": "none_available",
          "date": "2026-05-19T14:16:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-8954",
      "cwe": {
        "id": "CWE-190",
        "name": "Integer Overflow or Wraparound"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:\nIncorrect boundary conditions, integer overflow in the Audio/Video component",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-8954"
        }
      ],
      "release_date": "2026-05-19T14:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-23T10:30:52.854405Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649"
        },
        {
          "category": "none_available",
          "date": "2026-05-19T14:16:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-12311",
      "cwe": {
        "id": "CWE-200",
        "name": "Exposure of Sensitive Information to an Unauthorized Actor"
      },
      "notes": [
        {
          "category": "description",
          "text": "Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
          "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-12311"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.mozilla.org/show_bug.cgi?id=2040177",
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2040177"
        },
        {
          "category": "external",
          "summary": "https://www.mozilla.org/security/advisories/mfsa2026-57/",
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-57/"
        },
        {
          "category": "external",
          "summary": "https://www.mozilla.org/security/advisories/mfsa2026-58/",
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-58/"
        },
        {
          "category": "external",
          "summary": "https://www.mozilla.org/security/advisories/mfsa2026-60/",
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-60/"
        },
        {
          "category": "external",
          "summary": "https://www.mozilla.org/security/advisories/mfsa2026-61/",
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-61/"
        }
      ],
      "release_date": "2026-06-16T13:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-23T10:30:52.854405Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els13.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1782210649"
        },
        {
          "category": "none_available",
          "date": "2026-06-16T13:16:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els10.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els4.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els7.x86_64",
            "AlmaLinux-9.2:thunderbird-0:115.4.1-1.el9_2.alma.tuxcare.els9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    }
  ]
}