﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
21566	thunderbird-128.10.1esr	Joe Locash	zeckma	"**What’s Fixed**
 - Standalone message windows/tabs no longer responded after folder compaction
 - Thunderbird could crash when importing Outlook messages
 - Visual and UX improvements

**Security fixes**
 https://www.mozilla.org/en-US/security/advisories/mfsa2025-34/
 - CVE-2025-3875: Sender Spoofing via Malformed From Header in Thunderbird (high)
 - CVE-2025-3877: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links (high)
 - CVE-2025-3909: JavaScript Execution via Spoofed PDF Attachment and file:/// Link (high)
 - CVE-2025-3932: Tracking Links in Attachments Bypassed Remote Content Blocking (low)
"	enhancement	closed	high	12.4	BOOK	git	medium	fixed		
