﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
22269	thunderbird-140.4.0esr	Joe Locash	zeckma	"**What’s Changed**
 - Account Hub is now disabled by default for second email account
 - Flatpak runtime has been updated to Freedesktop SDK 24.08

**What’s Fixed
** - Users could not read mail signed with OpenPGP v6 and PQC keys
 - Image preview in Insert Image dialog failed with CSP error for web resources
 - Emptying trash on exit did not work with some providers
 - Thunderbird could crash when applying filters
 - Users were unable to override expired mail server certificate
 - Opening Website header link in RSS feed incorrectly re-encoded URL parameters
**Security fixes**
https://www.mozilla.org/en-US/security/advisories/mfsa2025-85/

 - CVE-2025-11708: Use-after-free in MediaTrackGraphImpl::GetInstance() (high)
 - CVE-2025-11709: Out of bounds read/write in a privileged process triggered by WebGL textures (high)
 - CVE-2025-11710: Cross-process information leaked due to malicious IPC messages (high)
 - CVE-2025-11711: Some non-writable Object properties could be modified (high)
 - CVE-2025-11712: An OBJECT tag type attribute overrode browser behavior on web resources without a content-type (moderate)
 - CVE-2025-11713: Potential user-assisted code execution in “Copy as cURL” command (moderate)
 - CVE-2025-11714: Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144 (high)
 - CVE-2025-11715: Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144 (high)
"	enhancement	closed	high	13.0	BOOK	git	medium	fixed		
