<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2026-0055</id>
    <title>An update for firefox is now available for HCE 2.0</title>
    <severity>Critical</severity>
    <release>HCE 2.0</release>
    <issued date="2026-03-23 23:18:31"/>
    <updated date="2026-03-23 23:18:31"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-9179" id="CVE-2025-9179" title="CVE-2025-9179 Base Score: 9.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-10532" id="CVE-2025-10532" title="CVE-2025-10532 Base Score: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-14327" id="CVE-2025-14327" title="CVE-2025-14327 Base Score: 7.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-8038" id="CVE-2025-8038" title="CVE-2025-8038 Base Score: 9.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-13017" id="CVE-2025-13017" title="CVE-2025-13017 Base Score: 8.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-9182" id="CVE-2025-9182" title="CVE-2025-9182 Base Score: 7.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-10537" id="CVE-2025-10537" title="CVE-2025-10537 Base Score: 8.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-10528" id="CVE-2025-10528" title="CVE-2025-10528 Base Score: 7.3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-11710" id="CVE-2025-11710" title="CVE-2025-11710 Base Score: 9.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-10529" id="CVE-2025-10529" title="CVE-2025-10529 Base Score: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-9183" id="CVE-2025-9183" title="CVE-2025-9183 Base Score: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-11711" id="CVE-2025-11711" title="CVE-2025-11711 Base Score: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-10527" id="CVE-2025-10527" title="CVE-2025-10527 Base Score: 7.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-13013" id="CVE-2025-13013" title="CVE-2025-13013 Base Score: 6.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-11713" id="CVE-2025-11713" title="CVE-2025-11713 Base Score: 8.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-11715" id="CVE-2025-11715" title="CVE-2025-11715 Base Score: 8.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-9184" id="CVE-2025-9184" title="CVE-2025-9184 Base Score: 8.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-13019" id="CVE-2025-13019" title="CVE-2025-13019 Base Score: 8.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0884" id="CVE-2026-0884" title="CVE-2026-0884 Base Score: 9.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-8039" id="CVE-2025-8039" title="CVE-2025-8039 Base Score: 8.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0879" id="CVE-2026-0879" title="CVE-2026-0879 Base Score: 9.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0883" id="CVE-2026-0883" title="CVE-2026-0883 Base Score: 5.3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-10536" id="CVE-2025-10536" title="CVE-2025-10536 Base Score: 6.2 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0878" id="CVE-2026-0878" title="CVE-2026-0878 Base Score: 8.0 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-11709" id="CVE-2025-11709" title="CVE-2025-11709 Base Score: 9.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0891" id="CVE-2026-0891" title="CVE-2026-0891 Base Score: 8.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-13015" id="CVE-2025-13015" title="CVE-2025-13015 Base Score: 3.4 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-8040" id="CVE-2025-8040" title="CVE-2025-8040 Base Score: 8.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0890" id="CVE-2026-0890" title="CVE-2026-0890 Base Score: 5.4 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-13014" id="CVE-2025-13014" title="CVE-2025-13014 Base Score: 8.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0886" id="CVE-2026-0886" title="CVE-2026-0886 Base Score: 5.3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-9181" id="CVE-2025-9181" title="CVE-2025-9181 Base Score: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0882" id="CVE-2026-0882" title="CVE-2026-0882 Base Score: 8.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-13018" id="CVE-2025-13018" title="CVE-2025-13018 Base Score: 8.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-11708" id="CVE-2025-11708" title="CVE-2025-11708 Base Score: 9.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0877" id="CVE-2026-0877" title="CVE-2026-0877 Base Score: 8.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-11712" id="CVE-2025-11712" title="CVE-2025-11712 Base Score: 6.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-13016" id="CVE-2025-13016" title="CVE-2025-13016 Base Score: 7.5 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-13012" id="CVE-2025-13012" title="CVE-2025-13012 Base Score: 7.5 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0887" id="CVE-2026-0887" title="CVE-2026-0887 Base Score: 4.3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-10533" id="CVE-2025-10533" title="CVE-2025-10533 Base Score: 8.8 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-8037" id="CVE-2025-8037" title="CVE-2025-8037 Base Score: 9.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-8036" id="CVE-2025-8036" title="CVE-2025-8036 Base Score: 8.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-9185" id="CVE-2025-9185" title="CVE-2025-9185 Base Score: 8.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-9180" id="CVE-2025-9180" title="CVE-2025-9180 Base Score: 8.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0885" id="CVE-2026-0885" title="CVE-2026-0885 Base Score: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-13020" id="CVE-2025-13020" title="CVE-2025-13020 Base Score: 8.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2026-0880" id="CVE-2026-0880" title="CVE-2026-0880 Base Score: 8.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-11714" id="CVE-2025-11714" title="CVE-2025-11714 Base Score: 8.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox &lt; 142, Firefox ESR &lt; 115.27, Firefox ESR &lt; 128.14, Firefox ESR &lt; 140.2, Thunderbird &lt; 142, Thunderbird &lt; 128.14, and Thunderbird &lt; 140.2. (CVE-2025-9179)

Incorrect boundary conditions in the _ GC component. This vulnerability affects Firefox &lt; 143, Firefox ESR &lt; 140.3, Thunderbird &lt; 143, and Thunderbird &lt; 140.3. (CVE-2025-10532)

Spoofing issue in the Downloads Panel component. This vulnerability affects Firefox &lt; 146, Thunderbird &lt; 146, Firefox ESR &lt; 140.7, and Thunderbird &lt; 140.7. (CVE-2025-14327)

Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability affects Firefox &lt; 141, Firefox ESR &lt; 140.1, Thunderbird &lt; 141, and Thunderbird &lt; 140.1. (CVE-2025-8038)

Same-origin policy bypass in the DOM: Notifications component. This vulnerability affects Firefox &lt; 145, Firefox ESR &lt; 140.5, Thunderbird &lt; 145, and Thunderbird &lt; 140.5. (CVE-2025-13017)

Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability affects Firefox &lt; 142, Firefox ESR &lt; 140.2, Thunderbird &lt; 142, and Thunderbird &lt; 140.2. (CVE-2025-9182)

Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &lt; 143, Firefox ESR &lt; 140.3, Thunderbird &lt; 143, and Thunderbird &lt; 140.3. (CVE-2025-10537)

Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability affects Firefox &lt; 143, Firefox ESR &lt; 140.3, Thunderbird &lt; 143, and Thunderbird &lt; 140.3. (CVE-2025-10528)

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability affects Firefox &lt; 144, Firefox ESR &lt; 115.29, Firefox ESR &lt; 140.4, Thunderbird &lt; 144, and Thunderbird &lt; 140.4. (CVE-2025-11710)

Same-origin policy bypass in the Layout component. This vulnerability affects Firefox &lt; 143, Firefox ESR &lt; 140.3, Thunderbird &lt; 143, and Thunderbird &lt; 140.3. (CVE-2025-10529)

Spoofing issue in the Address Bar component. This vulnerability affects Firefox &lt; 142 and Firefox ESR &lt; 140.2. (CVE-2025-9183)

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability affects Firefox &lt; 144, Firefox ESR &lt; 115.29, Firefox ESR &lt; 140.4, Thunderbird &lt; 144, and Thunderbird &lt; 140.4. (CVE-2025-11711)

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox &lt; 143, Firefox ESR &lt; 140.3, Thunderbird &lt; 143, and Thunderbird &lt; 140.3. (CVE-2025-10527)

Mitigation bypass in the DOM: Core &amp; HTML component. This vulnerability affects Firefox &lt; 145, Firefox ESR &lt; 140.5, Firefox ESR &lt; 115.30, Thunderbird &lt; 145, and Thunderbird &lt; 140.5. (CVE-2025-13013)

Insufficient escaping in the â€œCopy as cURLâ€ feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability affects Firefox &lt; 144, Firefox ESR &lt; 140.4, Thunderbird &lt; 144, and Thunderbird &lt; 140.4. (CVE-2025-11713)

Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &lt; 144, Firefox ESR &lt; 140.4, Thunderbird &lt; 144, and Thunderbird &lt; 140.4. (CVE-2025-11715)

Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &lt; 142, Firefox ESR &lt; 140.2, Thunderbird &lt; 142, and Thunderbird &lt; 140.2. (CVE-2025-9184)

Same-origin policy bypass in the DOM: Workers component. This vulnerability affects Firefox &lt; 145, Firefox ESR &lt; 140.5, Thunderbird &lt; 145, and Thunderbird &lt; 140.5. (CVE-2025-13019)

Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox &lt; 147, Firefox ESR &lt; 140.7, Thunderbird &lt; 147, and Thunderbird &lt; 140.7. (CVE-2026-0884)

In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability affects Firefox &lt; 141, Firefox ESR &lt; 140.1, Thunderbird &lt; 141, and Thunderbird &lt; 140.1. (CVE-2025-8039)

Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox &lt; 147, Firefox ESR &lt; 115.32, Firefox ESR &lt; 140.7, Thunderbird &lt; 147, and Thunderbird &lt; 140.7. (CVE-2026-0879)

Information disclosure in the Networking component. This vulnerability affects Firefox &lt; 147, Firefox ESR &lt; 140.7, Thunderbird &lt; 147, and Thunderbird &lt; 140.7. (CVE-2026-0883)

Information disclosure in the Networking: Cache component. This vulnerability affects Firefox &lt; 143, Firefox ESR &lt; 140.3, Thunderbird &lt; 143, and Thunderbird &lt; 140.3. (CVE-2025-10536)

Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability affects Firefox &lt; 147, Firefox ESR &lt; 140.7, Thunderbird &lt; 147, and Thunderbird &lt; 140.7. (CVE-2026-0878)

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox &lt; 144, Firefox ESR &lt; 115.29, Firefox ESR &lt; 140.4, Thunderbird &lt; 144, and Thunderbird &lt; 140.4. (CVE-2025-11709)

Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &lt; 147, Firefox ESR &lt; 140.7, Thunderbird &lt; 147, and Thunderbird &lt; 140.7. (CVE-2026-0891)

Spoofing issue in Firefox. This vulnerability affects Firefox &lt; 145, Firefox ESR &lt; 140.5, Firefox ESR &lt; 115.30, Thunderbird &lt; 145, and Thunderbird &lt; 140.5. (CVE-2025-13015)

Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &lt; 141, Firefox ESR &lt; 140.1, Thunderbird &lt; 141, and Thunderbird &lt; 140.1. (CVE-2025-8040)

Spoofing issue in the DOM: Copy &amp; Paste and Drag &amp; Drop component. This vulnerability affects Firefox &lt; 147, Firefox ESR &lt; 140.7, Thunderbird &lt; 147, and Thunderbird &lt; 140.7. (CVE-2026-0890)

Use-after-free in the Audio/Video component. This vulnerability affects Firefox &lt; 145, Firefox ESR &lt; 140.5, Firefox ESR &lt; 115.30, Thunderbird &lt; 145, and Thunderbird &lt; 140.5. (CVE-2025-13014)

Incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox &lt; 147, Firefox ESR &lt; 115.32, Firefox ESR &lt; 140.7, Thunderbird &lt; 147, and Thunderbird &lt; 140.7. (CVE-2026-0886)

Uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox &lt; 142, Firefox ESR &lt; 128.14, Firefox ESR &lt; 140.2, Thunderbird &lt; 142, Thunderbird &lt; 128.14, and Thunderbird &lt; 140.2. (CVE-2025-9181)

Use-after-free in the IPC component. This vulnerability affects Firefox &lt; 147, Firefox ESR &lt; 115.32, Firefox ESR &lt; 140.7, Thunderbird &lt; 147, and Thunderbird &lt; 140.7. (CVE-2026-0882)

Mitigation bypass in the DOM: Security component. This vulnerability affects Firefox &lt; 145, Firefox ESR &lt; 140.5, Thunderbird &lt; 145, and Thunderbird &lt; 140.5. (CVE-2025-13018)

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox &lt; 144, Firefox ESR &lt; 140.4, Thunderbird &lt; 144, and Thunderbird &lt; 140.4. (CVE-2025-11708)

Mitigation bypass in the DOM: Security component. This vulnerability affects Firefox &lt; 147, Firefox ESR &lt; 115.32, Firefox ESR &lt; 140.7, Thunderbird &lt; 147, and Thunderbird &lt; 140.7. (CVE-2026-0877)

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header. This vulnerability affects Firefox &lt; 144, Firefox ESR &lt; 140.4, Thunderbird &lt; 144, and Thunderbird &lt; 140.4. (CVE-2025-11712)

Incorrect boundary conditions in the _ WebAssembly component. This vulnerability affects Firefox &lt; 145, Firefox ESR &lt; 140.5, Thunderbird &lt; 145, and Thunderbird &lt; 140.5. (CVE-2025-13016)

Race condition in the Graphics component. This vulnerability affects Firefox &lt; 145, Firefox ESR &lt; 140.5, Firefox ESR &lt; 115.30, Thunderbird &lt; 145, and Thunderbird &lt; 140.5. (CVE-2025-13012)

Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability affects Firefox &lt; 147, Firefox ESR &lt; 140.7, Thunderbird &lt; 147, and Thunderbird &lt; 140.7. (CVE-2026-0887)

Integer overflow in the SVG component. This vulnerability affects Firefox &lt; 143, Firefox ESR &lt; 115.28, Firefox ESR &lt; 140.3, Thunderbird &lt; 143, and Thunderbird &lt; 140.3. (CVE-2025-10533)

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox &lt; 141, Firefox ESR &lt; 140.1, Thunderbird &lt; 141, and Thunderbird &lt; 140.1. (CVE-2025-8037)

Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability affects Firefox &lt; 141, Firefox ESR &lt; 140.1, Thunderbird &lt; 141, and Thunderbird &lt; 140.1. (CVE-2025-8036)

Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &lt; 142, Firefox ESR &lt; 115.27, Firefox ESR &lt; 128.14, Firefox ESR &lt; 140.2, Thunderbird &lt; 142, Thunderbird &lt; 128.14, and Thunderbird &lt; 140.2. (CVE-2025-9185)

Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability affects Firefox &lt; 142, Firefox ESR &lt; 115.27, Firefox ESR &lt; 128.14, Firefox ESR &lt; 140.2, Thunderbird &lt; 142, Thunderbird &lt; 128.14, and Thunderbird &lt; 140.2. (CVE-2025-9180)

Use-after-free in the _ GC component. This vulnerability affects Firefox &lt; 147, Firefox ESR &lt; 140.7, Thunderbird &lt; 147, and Thunderbird &lt; 140.7. (CVE-2026-0885)

Use-after-free in the WebRTC: Audio/Video component. This vulnerability affects Firefox &lt; 145, Firefox ESR &lt; 140.5, Thunderbird &lt; 145, and Thunderbird &lt; 140.5. (CVE-2025-13020)

Sandbox escape due to integer overflow in the Graphics component. This vulnerability affects Firefox &lt; 147, Firefox ESR &lt; 115.32, Firefox ESR &lt; 140.7, Thunderbird &lt; 147, and Thunderbird &lt; 140.7. (CVE-2026-0880)

Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &lt; 144, Firefox ESR &lt; 115.29, Firefox ESR &lt; 140.4, Thunderbird &lt; 144, and Thunderbird &lt; 140.4. (CVE-2025-11714)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="firefox">
        <name>HCE 2.0</name>
        <package arch="x86_64" name="firefox" version="140.8.0" release="1.hce2">
          <filename>firefox-140.8.0-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="aarch64" name="firefox" version="140.8.0" release="1.hce2">
          <filename>firefox-140.8.0-1.hce2.aarch64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
