Thunderbird Security Update — AlmaLinux 9 (ALSA-2026:49921)
Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): * firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719) * firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718) * firefox: thunderbird: Mitigat…
Mozilla Thunderbird is a standalone mail and newsgroup client.
Security Fix(es):
* firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719)
* firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718)
* firefox: thunderbird: Mitigat…
Security Fix(es):
* firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719)
* firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718)
* firefox: thunderbird: Mitigation bypass in the Enterprise Policies component (CVE-2026-16390)
* firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: cubeb component (CVE-2026-16350)
* firefox: thunderbird: Information disclosure in the Storage: IndexedDB component (CVE-2026-16391)
* firefox: thunderbird: Site isolation issue in the Networking: HTTP component (CVE-2026-16375)
* firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16356)
* firefox: thunderbird: JIT miscompilation in the JavaScript: WebAssembly component (CVE-2026-16363)
* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 (CVE-2026-16412)
* firefox: thunderbird: Same-origin policy bypass in the Networking: DNS component (CVE-2026-16381)
* firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-16355)
* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 (CVE-2026-16361)
* firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16352)
* firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component (CVE-2026-16368)
* firefox: thunderbird: Mitigation bypass in the PDF Viewer component (CVE-2026-16377)
* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 (CVE-2026-16360)
* firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component (CVE-2026-16362)
* firefox: thunderbird: Site isolation issue in the Graphics: WebRender component (CVE-2026-16358)
* firefox: thunderbird: Site isolation issue in the Networking component (CVE-2026-16387)
* firefox: thunderbird: Same-origin policy bypass in the DOM: Navigation component (CVE-2026-16349)
* firefox: thunderbird: Incorrect boundary conditions in the Graphics component (CVE-2026-16357)
* firefox: thunderbird: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-16351)
* firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-16371)
* firefox: thunderbird: Privilege escalation in the DOM: Content Processes component (CVE-2026-16379)
* firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-16354)
* firefox: thunderbird: Information disclosure in the Framework component in DevTools (CVE-2026-16374)
* firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: GMP component (CVE-2026-16359)
* firefox: thunderbird: Mitigation bypass in the DOM: Networking component (CVE-2026-16383)
* firefox: thunderbird: Integer overflow in the JavaScript: WebAssembly component (CVE-2026-16369)
* firefox: thunderbird: Invalid pointer in the DOM: Bindings (WebIDL) component (CVE-2026-16353)
* firefox: thunderbird: Privilege escalation in WebExtensions (CVE-2026-16396)
* firefox: thunderbird: Information disclosure in the Networking: WebSockets component (CVE-2026-16405)
* thunderbird: Off-by-one out of bounds read in MIME header parser for forwarding (CVE-2026-14899)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
- CVE-2026-14899
- CVE-2026-15718
- CVE-2026-15719
- CVE-2026-16349
- CVE-2026-16350
- CVE-2026-16351
- CVE-2026-16352
- CVE-2026-16353
- CVE-2026-16354
- CVE-2026-16355
- CVE-2026-16356
- CVE-2026-16357
- CVE-2026-16358
- CVE-2026-16359
- CVE-2026-16360
- CVE-2026-16361
- CVE-2026-16362
- CVE-2026-16363
- CVE-2026-16368
- CVE-2026-16369
- CVE-2026-16371
- CVE-2026-16374
- CVE-2026-16375
- CVE-2026-16377
- CVE-2026-16379
- CVE-2026-16381
- CVE-2026-16383
- CVE-2026-16387
- CVE-2026-16390
- CVE-2026-16391
- CVE-2026-16396
- CVE-2026-16405
- CVE-2026-16412
- RHSA-2026:49921
- ALSA-2026:49921
| Architecture | Package | Checksum |
| aarch64 | thunderbird-140.13.0-1.el9_8.alma.1.aarch64.rpm | 1bddacb878b0f0ce36bae41d0a6da13b3d1c142961983a346168d80d2133075f |
| ppc64le | thunderbird-140.13.0-1.el9_8.alma.1.ppc64le.rpm | e4f1abc6cf21d1f9aea0c3ec08cd4a5d878c937606d735fe06a68d1343ad2399 |
| s390x | thunderbird-140.13.0-1.el9_8.alma.1.s390x.rpm | 1320b4402cac5467c6d5dd740a6c34eb1ada630c5b994367f7b5cbb9b08133c1 |
| x86_64 | thunderbird-140.13.0-1.el9_8.alma.1.x86_64.rpm | bdc7706b5d6ec250882c5fa51259a839a2d50f576f11b3ddd43e16ac8988e3b7 |
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System