{"cve": "CVE-2026-8959", "updated": null, "url": null, "affected": [{"ecosystem": "openSUSE:Tumbleweed", "package": "MozillaFirefox", "affected": null, "fixed": "151.0.1-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:10863-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "MozillaThunderbird", "affected": null, "fixed": "140.11.1-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:10864-1"}, {"ecosystem": "openSUSE:Leap 16.0", "package": "MozillaThunderbird", "affected": null, "fixed": "140.12.0-bp160.1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:21168-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "firefox-esr", "affected": null, "fixed": "140.11.0-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2026:10813-1"}, {"ecosystem": "Red Hat:enterprise_linux:9::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.11.0-1.el9_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:21381"}, {"ecosystem": "Red Hat:enterprise_linux:10.2", "package": "thunderbird", "affected": null, "fixed": "0:140.11.0-1.el10_2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:22325"}, {"ecosystem": "Red Hat:enterprise_linux:8::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.11.0-1.el8_10", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:22643"}, {"ecosystem": "Red Hat:rhel_e4s:9.4::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.11.0-1.el9_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:26174"}, {"ecosystem": "Red Hat:rhel_e4s:8.8::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.11.0-1.el8_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:26268"}, {"ecosystem": "Red Hat:rhel_tus:8.8::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.11.0-1.el8_8", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:26268"}, {"ecosystem": "Red Hat:rhel_e4s:9.2::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.11.0-1.el9_2", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:26269"}, {"ecosystem": "Red Hat:rhel_aus:8.4::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.11.0-1.el8_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:26270"}, {"ecosystem": "Red Hat:rhel_eus_long_life:8.4::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.11.0-1.el8_4", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:26270"}, {"ecosystem": "Red Hat:rhel_eus:9.6::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.11.0-1.el9_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:26521"}, {"ecosystem": "Red Hat:rhel_aus:8.6::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.11.0-1.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:26536"}, {"ecosystem": "Red Hat:rhel_eus_long_life:8.6::appstream", "package": "thunderbird", "affected": null, "fixed": "0:140.11.0-1.el8_6", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:26536"}, {"ecosystem": "Red Hat:enterprise_linux_eus:10.0", "package": "thunderbird", "affected": null, "fixed": "0:140.11.0-1.el10_0", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2026:26539"}]}