{"cve": "CVE-2026-6766", "updated": null, "url": null, "affected": [{"ecosystem": "Debian:11", "package": "firefox-esr", "affected": null, "fixed": "140.10.0esr-1~deb11u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2026-6766"}, {"ecosystem": "Debian:12", "package": "firefox-esr", "affected": null, "fixed": "140.10.0esr-1~deb12u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2026-6766"}, {"ecosystem": "Debian:13", "package": "firefox-esr", "affected": null, "fixed": "140.10.0esr-1~deb13u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2026-6766"}, {"ecosystem": "Debian:14", "package": "firefox-esr", "affected": null, "fixed": "140.10.0esr-1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2026-6766"}, {"ecosystem": "Debian:11", "package": "thunderbird", "affected": null, "fixed": "1:140.10.0esr-1~deb11u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2026-6766"}, {"ecosystem": "Debian:12", "package": "thunderbird", "affected": null, "fixed": "1:140.10.0esr-1~deb12u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2026-6766"}, {"ecosystem": "Debian:13", "package": "thunderbird", "affected": null, "fixed": "1:140.10.0esr-1~deb13u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2026-6766"}, {"ecosystem": "Debian:14", "package": "thunderbird", "affected": null, "fixed": "1:140.10.0esr-1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2026-6766"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "MozillaFirefox", "affected": null, "fixed": "150.0-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:10626-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "MozillaThunderbird", "affected": null, "fixed": "140.9.1-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:10610-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "firefox-esr", "affected": null, "fixed": "153.0-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:11373-1"}, {"ecosystem": "Red Hat:enterprise_linux:9::appstream", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el9_7", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:10757"}, {"ecosystem": "Red Hat:enterprise_linux:8::appstream", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el8_10", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:10766"}, {"ecosystem": "Red Hat:enterprise_linux:10.1", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el10_1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:10767"}, {"ecosystem": "Red Hat:rhel_e4s:8.8::appstream", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el8_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:17477"}, {"ecosystem": "Red Hat:rhel_tus:8.8::appstream", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el8_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:17477"}, {"ecosystem": "Red Hat:rhel_e4s:9.0::appstream", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el9_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:17687"}, {"ecosystem": "Red Hat:rhel_eus:9.6::appstream", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el9_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:17688"}, {"ecosystem": "Red Hat:rhel_e4s:9.2::appstream", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el9_2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:17689"}, {"ecosystem": "Red Hat:enterprise_linux_eus:10.0", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el10_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:17690"}, {"ecosystem": "Red Hat:enterprise_linux:10.2", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el10_2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19041"}, {"ecosystem": "Red Hat:enterprise_linux:9::appstream", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el9_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19201"}, {"ecosystem": "Red Hat:rhel_eus:9.4::appstream", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el9_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19464"}, {"ecosystem": "Red Hat:rhel_aus:8.6::appstream", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19542"}, {"ecosystem": "Red Hat:rhel_e4s:8.6::appstream", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19542"}, {"ecosystem": "Red Hat:rhel_tus:8.6::appstream", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19542"}, {"ecosystem": "Red Hat:rhel_aus:8.4::appstream", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el8_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19655"}, {"ecosystem": "Red Hat:rhel_eus_long_life:8.4::appstream", "package": "firefox", "affected": null, "fixed": "0:140.10.0-1.el8_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19655"}, {"ecosystem": "Red Hat:rhel_els:7", "package": "firefox", "affected": null, "fixed": "0:140.10.0-2.el7_9", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19704"}, {"ecosystem": "Red Hat:enterprise_linux:10.1", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el10_1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:12285"}, {"ecosystem": "Red Hat:enterprise_linux:8::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el8_10", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:13537"}, {"ecosystem": "Red Hat:enterprise_linux:9::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el9_7", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:15892"}, {"ecosystem": "Red Hat:enterprise_linux:10.2", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el10_2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19131"}, {"ecosystem": "Red Hat:enterprise_linux:9::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.10.1-1.el9_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19348"}, {"ecosystem": "Red Hat:rhel_e4s:9.2::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el9_2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19461"}, {"ecosystem": "Red Hat:rhel_eus:9.6::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el9_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19462"}, {"ecosystem": "Red Hat:enterprise_linux_eus:10.0", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el10_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19463"}, {"ecosystem": "Red Hat:rhel_aus:8.4::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el8_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19465"}, {"ecosystem": "Red Hat:rhel_eus_long_life:8.4::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el8_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19465"}, {"ecosystem": "Red Hat:rhel_aus:8.6::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19466"}, {"ecosystem": "Red Hat:rhel_e4s:8.6::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19466"}, {"ecosystem": "Red Hat:rhel_tus:8.6::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19466"}, {"ecosystem": "Red Hat:rhel_e4s:8.8::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el8_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19467"}, {"ecosystem": "Red Hat:rhel_tus:8.8::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el8_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19467"}, {"ecosystem": "Red Hat:rhel_e4s:9.0::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el9_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19468"}, {"ecosystem": "Red Hat:rhel_eus:9.4::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.10.0-1.el9_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:19469"}]}