{"schema_version":"1.7.5","id":"CGA-hhf2-mg4x-8h5q","published":"2026-07-01T10:23:03Z","modified":"2026-09-07T02:04:03.371249193Z","withdrawn":"2026-09-07T02:04:03.371248988Z","related":["CVE-2025-13017","GHSA-8prr-wp36-5mv2"],"affected":[{"package":{"name":"firefox","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/firefox"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.5-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-hhf2-mg4x-8h5q.json"}},{"package":{"name":"firefox-esr","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/firefox-esr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.5-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-hhf2-mg4x-8h5q.json"}},{"package":{"name":"firefox","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/firefox"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.5-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-hhf2-mg4x-8h5q.json"}}]}