View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2026-2765 severity important: SUSE including 46 source package names (13.2-9.16:rpm-4.18.0-7.1, 2.1.3-6.52:rpm-4.18.0-7.1, …), 149 product×package rows across 53 product lines (Container suse/sl-micro/6.0/baremetal-os-container, Container suse/sl-micro/6.0/base-os-container, … (53 product lines)): Fixed 145, First Fixed 4.
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.