RHSA-2026:49621HighCVSS 8.8

Red Hat Security Advisory: thunderbird security update

Published
August 3, 2026
Last Modified
August 12, 2026

🔗 CVE IDs covered (33)

📋 Description

CVE-2026-14899 — thunderbird: Off-by-one out of bounds read in MIME header parser for forwarding CVE-2026-15718 — firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719 — firefox: thunderbird: Site isolation issue in the DOM: Navigation component CVE-2026-16349 — firefox: thunderbird: Same-origin policy bypass in the DOM: Navigation component CVE-2026-16350 — firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: cubeb component CVE-2026-16351 — firefox: thunderbird: Sandbox escape due to use-after-free in the DOM: Navigation component CVE-2026-16352 — firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component CVE-2026-16353 — firefox: thunderbird: Invalid pointer in the DOM: Bindings (WebIDL) component CVE-2026-16354 — firefox: thunderbird: Information disclosure in the Graphics: ImageLib component CVE-2026-16355 — firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component CVE-2026-16356 — firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component CVE-2026-16357 — firefox: thunderbird: Incorrect boundary conditions in the Graphics component CVE-2026-16358 — firefox: thunderbird: Site isolation issue in the Graphics: WebRender component CVE-2026-16359 — firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: GMP component CVE-2026-16360 — firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 CVE-2026-16361 — firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 CVE-2026-16362 — firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component CVE-2026-16363 — firefox: thunderbird: JIT miscompilation in the JavaScript: WebAssembly component CVE-2026-16368 — firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component CVE-2026-16369 — firefox: thunderbird: Integer overflow in the JavaScript: WebAssembly component CVE-2026-16371 — firefox: thunderbird: Privilege escalation in the DOM: Navigation component CVE-2026-16374 — firefox: thunderbird: Information disclosure in the Framework component in DevTools CVE-2026-16375 — firefox: thunderbird: Site isolation issue in the Networking: HTTP component CVE-2026-16377 — firefox: thunderbird: Mitigation bypass in the PDF Viewer component CVE-2026-16379 — firefox: thunderbird: Privilege escalation in the DOM: Content Processes component CVE-2026-16381 — firefox: thunderbird: Same-origin policy bypass in the Networking: DNS component CVE-2026-16383 — firefox: thunderbird: Mitigation bypass in the DOM: Networking component CVE-2026-16387 — firefox: thunderbird: Site isolation issue in the Networking component CVE-2026-16390 — firefox: thunderbird: Mitigation bypass in the Enterprise Policies component CVE-2026-16391 — firefox: thunderbird: Information disclosure in the Storage: IndexedDB component CVE-2026-16396 — firefox: thunderbird: Privilege escalation in WebExtensions CVE-2026-16405 — firefox: thunderbird: Information disclosure in the Networking: WebSockets component CVE-2026-16412 — firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153

🎯 Affected products14

  • Red Hat Enterprise Linux AppStream (v. 10)
  • thunderbird-0:140.13.0-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • thunderbird-0:140.13.0-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • thunderbird-0:140.13.0-1.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • thunderbird-0:140.13.0-1.el10_2.src as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • thunderbird-0:140.13.0-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • thunderbird-debuginfo-0:140.13.0-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • thunderbird-debuginfo-0:140.13.0-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • thunderbird-debuginfo-0:140.13.0-1.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • thunderbird-debuginfo-0:140.13.0-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • thunderbird-debugsource-0:140.13.0-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • thunderbird-debugsource-0:140.13.0-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • thunderbird-debugsource-0:140.13.0-1.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • thunderbird-debugsource-0:140.13.0-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (36)