{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"Critical"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"firefox security update",
				"category":"general",
				"title":"Synopsis"
			},
			{
				"text":"An update for firefox is now available for openEuler-24.03-LTS-SP4",
				"category":"general",
				"title":"Summary"
			},
			{
				"text":"Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.\n\nSecurity Fix(es):\n\nUse-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92005)\n\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92006)\n\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92007)\n\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92008)\n\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92009)\n\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92010)\n\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92011)\n\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92012)\n\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92013)\n\nPrivilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 115.41, Firefox ESR 140.16, and Thunderbird 140.16.(CVE-2026-92014)\n\nPrivilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92015)\n\nUse-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92016)\n\nPrivilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92017)\n\nSandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92018)\n\nMitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92019)\n\nPrivilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92020)\n\nUse-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 140.16 and Thunderbird 140.16.(CVE-2026-92021)\n\nUse-after-free in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92022)\n\nUse-after-free in the XML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92023)\n\nUse-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92024)\n\nUse-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92025)\n\nUse-after-free in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92026)\n\nUse-after-free in the DOM: Streams component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92027)\n\nUse-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92028)\n\nUse-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92029)\n\nMitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92030)\n\nInformation disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92031)\n\nSandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.(CVE-2026-92032)",
				"category":"general",
				"title":"Description"
			},
			{
				"text":"An update for firefox is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
				"category":"general",
				"title":"Topic"
			},
			{
				"text":"Critical",
				"category":"general",
				"title":"Severity"
			},
			{
				"text":"firefox",
				"category":"general",
				"title":"Affected Component"
			}
		],
		"publisher":{
			"issuing_authority":"openEuler security committee",
			"name":"openEuler",
			"namespace":"https://www.openeuler.org",
			"contact_details":"openeuler-security@openeuler.org",
			"category":"vendor"
		},
		"references":[
			{
				"summary":"openEuler-SA-2026-4123",
				"category":"self",
				"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
			},
			{
				"summary":"CVE-2026-92005",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92005&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92006",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92006&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92007",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92007&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92008",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92008&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92009",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92009&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92010",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92010&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92011",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92011&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92012",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92012&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92013",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92013&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92014",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92014&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92015",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92015&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92016",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92016&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92017",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92017&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92018",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92018&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92019",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92019&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92020",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92020&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92021",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92021&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92022",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92022&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92023",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92023&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92024",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92024&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92025",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92025&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92026",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92026&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92027",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92027&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92028",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92028&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92029",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92029&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92030",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92030&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92031",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92031&packageName=firefox"
			},
			{
				"summary":"CVE-2026-92032",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-92032&packageName=firefox"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92005"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92006"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92007"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92008"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92009"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92010"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92011"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92012"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92013"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92014"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92015"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92016"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92017"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92018"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92019"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92020"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92021"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92022"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92023"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92024"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92025"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92026"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92027"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92028"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92029"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92030"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92031"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92032"
			},
			{
				"summary":"openEuler-SA-2026-4123 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-4123.json"
			}
		],
		"title":"An update for firefox is now available for openEuler-24.03-LTS-SP4",
		"tracking":{
			"initial_release_date":"2026-09-30T16:01:20+08:00",
			"revision_history":[
				{
					"date":"2026-09-30T16:01:20+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				}
			],
			"generator":{
				"date":"2026-09-30T16:01:20+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2026-09-30T16:01:20+08:00",
			"id":"openEuler-SA-2026-4123",
			"version":"1.0.0",
			"status":"final"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP4"
									},
									"product_id":"openEuler-24.03-LTS-SP4",
									"name":"openEuler-24.03-LTS-SP4"
								},
								"name":"openEuler-24.03-LTS-SP4",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"aarch64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP4"
									},
									"product_id":"firefox-140.16.0-1.oe2403sp4.aarch64.rpm",
									"name":"firefox-140.16.0-1.oe2403sp4.aarch64.rpm"
								},
								"name":"firefox-140.16.0-1.oe2403sp4.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP4"
									},
									"product_id":"firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64.rpm",
									"name":"firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64.rpm"
								},
								"name":"firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP4"
									},
									"product_id":"firefox-debugsource-140.16.0-1.oe2403sp4.aarch64.rpm",
									"name":"firefox-debugsource-140.16.0-1.oe2403sp4.aarch64.rpm"
								},
								"name":"firefox-debugsource-140.16.0-1.oe2403sp4.aarch64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"src",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP4"
									},
									"product_id":"firefox-140.16.0-1.oe2403sp4.src.rpm",
									"name":"firefox-140.16.0-1.oe2403sp4.src.rpm"
								},
								"name":"firefox-140.16.0-1.oe2403sp4.src.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"x86_64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP4"
									},
									"product_id":"firefox-140.16.0-1.oe2403sp4.x86_64.rpm",
									"name":"firefox-140.16.0-1.oe2403sp4.x86_64.rpm"
								},
								"name":"firefox-140.16.0-1.oe2403sp4.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP4"
									},
									"product_id":"firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64.rpm",
									"name":"firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64.rpm"
								},
								"name":"firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP4"
									},
									"product_id":"firefox-debugsource-140.16.0-1.oe2403sp4.x86_64.rpm",
									"name":"firefox-debugsource-140.16.0-1.oe2403sp4.x86_64.rpm"
								},
								"name":"firefox-debugsource-140.16.0-1.oe2403sp4.x86_64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP4",
				"product_reference":"firefox-140.16.0-1.oe2403sp4.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"name":"firefox-140.16.0-1.oe2403sp4.aarch64 as a component of openEuler-24.03-LTS-SP4"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP4",
				"product_reference":"firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"name":"firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64 as a component of openEuler-24.03-LTS-SP4"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP4",
				"product_reference":"firefox-debugsource-140.16.0-1.oe2403sp4.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"name":"firefox-debugsource-140.16.0-1.oe2403sp4.aarch64 as a component of openEuler-24.03-LTS-SP4"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP4",
				"product_reference":"firefox-140.16.0-1.oe2403sp4.src.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"name":"firefox-140.16.0-1.oe2403sp4.src as a component of openEuler-24.03-LTS-SP4"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP4",
				"product_reference":"firefox-140.16.0-1.oe2403sp4.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"name":"firefox-140.16.0-1.oe2403sp4.x86_64 as a component of openEuler-24.03-LTS-SP4"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP4",
				"product_reference":"firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"name":"firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64 as a component of openEuler-24.03-LTS-SP4"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP4",
				"product_reference":"firefox-debugsource-140.16.0-1.oe2403sp4.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64",
					"name":"firefox-debugsource-140.16.0-1.oe2403sp4.x86_64 as a component of openEuler-24.03-LTS-SP4"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2026-92005",
			"notes":[
				{
					"text":"Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92005"
		},
		{
			"cve":"CVE-2026-92006",
			"notes":[
				{
					"text":"Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92006"
		},
		{
			"cve":"CVE-2026-92007",
			"notes":[
				{
					"text":"Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92007"
		},
		{
			"cve":"CVE-2026-92008",
			"notes":[
				{
					"text":"Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92008"
		},
		{
			"cve":"CVE-2026-92009",
			"notes":[
				{
					"text":"Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92009"
		},
		{
			"cve":"CVE-2026-92010",
			"notes":[
				{
					"text":"Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92010"
		},
		{
			"cve":"CVE-2026-92011",
			"notes":[
				{
					"text":"Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92011"
		},
		{
			"cve":"CVE-2026-92012",
			"notes":[
				{
					"text":"Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92012"
		},
		{
			"cve":"CVE-2026-92013",
			"notes":[
				{
					"text":"Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92013"
		},
		{
			"cve":"CVE-2026-92014",
			"notes":[
				{
					"text":"Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 115.41, Firefox ESR 140.16, and Thunderbird 140.16.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92014"
		},
		{
			"cve":"CVE-2026-92015",
			"notes":[
				{
					"text":"Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92015"
		},
		{
			"cve":"CVE-2026-92016",
			"notes":[
				{
					"text":"Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92016"
		},
		{
			"cve":"CVE-2026-92017",
			"notes":[
				{
					"text":"Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92017"
		},
		{
			"cve":"CVE-2026-92018",
			"notes":[
				{
					"text":"Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"CRITICAL",
						"baseScore":9.6,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"Critical",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92018"
		},
		{
			"cve":"CVE-2026-92019",
			"notes":[
				{
					"text":"Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"CRITICAL",
						"baseScore":9.1,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"Critical",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92019"
		},
		{
			"cve":"CVE-2026-92020",
			"notes":[
				{
					"text":"Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92020"
		},
		{
			"cve":"CVE-2026-92021",
			"notes":[
				{
					"text":"Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 140.16 and Thunderbird 140.16.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92021"
		},
		{
			"cve":"CVE-2026-92022",
			"notes":[
				{
					"text":"Use-after-free in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92022"
		},
		{
			"cve":"CVE-2026-92023",
			"notes":[
				{
					"text":"Use-after-free in the XML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92023"
		},
		{
			"cve":"CVE-2026-92024",
			"notes":[
				{
					"text":"Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92024"
		},
		{
			"cve":"CVE-2026-92025",
			"notes":[
				{
					"text":"Use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92025"
		},
		{
			"cve":"CVE-2026-92026",
			"notes":[
				{
					"text":"Use-after-free in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92026"
		},
		{
			"cve":"CVE-2026-92027",
			"notes":[
				{
					"text":"Use-after-free in the DOM: Streams component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92027"
		},
		{
			"cve":"CVE-2026-92028",
			"notes":[
				{
					"text":"Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92028"
		},
		{
			"cve":"CVE-2026-92029",
			"notes":[
				{
					"text":"Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92029"
		},
		{
			"cve":"CVE-2026-92030",
			"notes":[
				{
					"text":"Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"CRITICAL",
						"baseScore":9.1,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"Critical",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92030"
		},
		{
			"cve":"CVE-2026-92031",
			"notes":[
				{
					"text":"Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":7.5,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92031"
		},
		{
			"cve":"CVE-2026-92032",
			"notes":[
				{
					"text":"Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
					"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
					"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					],
					"details":"firefox security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4123"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"CRITICAL",
						"baseScore":10.0,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.aarch64",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.src",
						"openEuler-24.03-LTS-SP4:firefox-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debuginfo-140.16.0-1.oe2403sp4.x86_64",
						"openEuler-24.03-LTS-SP4:firefox-debugsource-140.16.0-1.oe2403sp4.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"Critical",
					"category":"impact"
				}
			],
			"title":"CVE-2026-92032"
		}
	]
}