{"cve": "CVE-2026-8949", "updated": null, "url": null, "affected": [{"ecosystem": "openSUSE:Tumbleweed", "package": "MozillaFirefox", "affected": null, "fixed": "151.0.1-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:10863-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "MozillaThunderbird", "affected": null, "fixed": "140.11.1-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:10864-1"}, {"ecosystem": "openSUSE:Leap 16.0", "package": "MozillaThunderbird", "affected": null, "fixed": "140.12.0-bp160.1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:21168-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "firefox-esr", "affected": null, "fixed": "140.11.0-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:10813-1"}]}