{"cve": "CVE-2026-33636", "updated": null, "url": null, "affected": [{"ecosystem": "Red Hat:rhel_aus:8.2::appstream", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el8_2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:11805"}, {"ecosystem": "Red Hat:rhel_eus:9.4::appstream", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el9_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13582"}, {"ecosystem": "Red Hat:rhel_eus:9.6::appstream", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el9_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13583"}, {"ecosystem": "Red Hat:rhel_e4s:9.0::appstream", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el9_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13596"}, {"ecosystem": "Red Hat:rhel_aus:8.4::appstream", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el8_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13600"}, {"ecosystem": "Red Hat:rhel_eus_long_life:8.4::appstream", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el8_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13600"}, {"ecosystem": "Red Hat:enterprise_linux_eus:10.0", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el10_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13665"}, {"ecosystem": "Red Hat:rhel_e4s:8.8::appstream", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el8_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13682"}, {"ecosystem": "Red Hat:rhel_tus:8.8::appstream", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el8_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13682"}, {"ecosystem": "Red Hat:rhel_aus:8.6::appstream", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13683"}, {"ecosystem": "Red Hat:rhel_e4s:8.6::appstream", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13683"}, {"ecosystem": "Red Hat:rhel_tus:8.6::appstream", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13683"}, {"ecosystem": "Red Hat:rhel_e4s:9.2::appstream", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el9_2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13922"}, {"ecosystem": "Red Hat:rhel_els:7", "package": "firefox", "affected": null, "fixed": "0:140.9.1-2.el7_9", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13977"}, {"ecosystem": "Red Hat:enterprise_linux:9::appstream", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el9_7", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:7671"}, {"ecosystem": "Red Hat:enterprise_linux:10.1", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el10_1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:7672"}, {"ecosystem": "Red Hat:enterprise_linux:8::appstream", "package": "firefox", "affected": null, "fixed": "0:140.9.1-1.el8_10", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:8052"}, {"ecosystem": "Red Hat:enterprise_linux_eus:10.0", "package": "thunderbird", "affected": null, "fixed": "0:140.9.1-1.el10_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:11813"}, {"ecosystem": "Red Hat:rhel_e4s:9.0::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.9.1-1.el9_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:12264"}, {"ecosystem": "Red Hat:rhel_eus:9.6::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.9.1-1.el9_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13342"}, {"ecosystem": "Red Hat:rhel_e4s:9.2::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.9.1-1.el9_2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13412"}, {"ecosystem": "Red Hat:rhel_eus:9.4::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.9.1-1.el9_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13533"}, {"ecosystem": "Red Hat:rhel_e4s:8.8::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.9.1-1.el8_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:14223"}, {"ecosystem": "Red Hat:rhel_tus:8.8::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.9.1-1.el8_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:14223"}, {"ecosystem": "Red Hat:rhel_aus:8.4::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.9.1-1.el8_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:14303"}, {"ecosystem": "Red Hat:rhel_eus_long_life:8.4::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.9.1-1.el8_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:14303"}, {"ecosystem": "Red Hat:rhel_aus:8.6::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.9.1-1.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:15889"}, {"ecosystem": "Red Hat:rhel_e4s:8.6::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.9.1-1.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:15889"}, {"ecosystem": "Red Hat:rhel_tus:8.6::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.9.1-1.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:15889"}, {"ecosystem": "Red Hat:enterprise_linux:9::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.9.1-1.el9_7", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:8459"}, {"ecosystem": "Red Hat:enterprise_linux:8::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.9.1-1.el8_10", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:9345"}, {"ecosystem": "Red Hat:enterprise_linux:10.1", "package": "thunderbird", "affected": null, "fixed": "0:140.9.1-1.el10_1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:9638"}]}