{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-4686",
        "tracking": {
            "current_release_date": "2026-04-02T15:17:32.569309Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-4686",
            "initial_release_date": "2026-03-24T20:48:38.367804Z",
            "revision_history": [
                {
                    "date": "2026-03-24T20:48:38.367804Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| Products connected (3).| References created (4)."
                },
                {
                    "date": "2026-03-24T20:48:42.194981Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-24T20:49:23.022179Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| References created (4)."
                },
                {
                    "date": "2026-03-24T20:52:51.958864Z",
                    "number": "4",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| Products connected (1).| References created (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-24T20:54:09.797441Z",
                    "number": "5",
                    "summary": "CVSS created.| Products connected (3).| Product Identifiers created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-24T20:54:13.814986Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T20:54:31.322319Z",
                    "number": "7",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| Products connected (1).| References created (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-24T20:54:38.899433Z",
                    "number": "8",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| Products connected (1).| References created (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-24T20:55:33.897570Z",
                    "number": "9",
                    "summary": "Description removed for source.| Description created for source.| Products connected (2).| References created (2)."
                },
                {
                    "date": "2026-03-24T20:55:37.875336Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T21:27:20.464489Z",
                    "number": "11",
                    "summary": "Description removed for source.| Description created for source.| References created (2)."
                },
                {
                    "date": "2026-03-25T00:22:03.773492Z",
                    "number": "12",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| Products connected (1).| References created (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-25T00:22:26.191365Z",
                    "number": "13",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| Products connected (1).| References created (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-25T00:43:48.696788Z",
                    "number": "14",
                    "summary": "Source created.| CVE status created. (valid)| Products connected (2)."
                },
                {
                    "date": "2026-03-25T00:43:51.830892Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T03:25:15.488711Z",
                    "number": "16",
                    "summary": "Source connected.| CVE status created. (valid)"
                },
                {
                    "date": "2026-03-25T06:43:53.054631Z",
                    "number": "17",
                    "summary": "Description created for source."
                },
                {
                    "date": "2026-03-25T12:43:14.485536Z",
                    "number": "18",
                    "summary": "Products connected (2)."
                },
                {
                    "date": "2026-03-25T13:16:39.558014Z",
                    "number": "19",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (5).| References created (7)."
                },
                {
                    "date": "2026-03-25T13:16:42.371464Z",
                    "number": "20",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-26T00:43:16.970618Z",
                    "number": "21",
                    "summary": "Products connected (1).| Product Identifiers created (1).| Products removed (1)."
                },
                {
                    "date": "2026-03-26T00:43:19.060464Z",
                    "number": "22",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-26T00:47:10.234998Z",
                    "number": "23",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-26T00:47:12.382319Z",
                    "number": "24",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-26T08:06:40.383719Z",
                    "number": "25",
                    "summary": "Products connected (2).| References created (2)."
                },
                {
                    "date": "2026-03-26T08:06:42.283227Z",
                    "number": "26",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-26T08:27:39.360893Z",
                    "number": "27",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-26T13:39:03.946283Z",
                    "number": "28",
                    "summary": "CVSS created.| CWES updated (1).| Unknown change."
                },
                {
                    "date": "2026-03-26T13:39:07.673481Z",
                    "number": "29",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-27T00:32:42.458562Z",
                    "number": "30",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (4).| Product Remediations created (4).| Product Identifiers created (13).| Product Identifiers removed (13).| References created (45).| CWES updated (1)."
                },
                {
                    "date": "2026-03-27T00:32:48.226869Z",
                    "number": "31",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-27T00:33:57.263324Z",
                    "number": "32",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (5).| Product Remediations created (5).| Product Identifiers created (17).| Product Identifiers removed (17).| References created (45).| CWES updated (1)."
                },
                {
                    "date": "2026-03-27T00:35:23.488649Z",
                    "number": "33",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (4).| Product Remediations created (4).| Product Identifiers created (13).| Product Identifiers removed (13).| References created (45).| CWES updated (1)."
                },
                {
                    "date": "2026-03-27T00:43:07.528076Z",
                    "number": "34",
                    "summary": "Products connected (3).| Product Identifiers created (3).| Products removed (3)."
                },
                {
                    "date": "2026-03-27T00:43:10.119973Z",
                    "number": "35",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-27T09:05:41.146567Z",
                    "number": "36",
                    "summary": "Products connected (1).| References created (6)."
                },
                {
                    "date": "2026-03-27T09:05:46.886015Z",
                    "number": "37",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-30T13:22:07.602199Z",
                    "number": "38",
                    "summary": "Products connected (2).| References created (5)."
                },
                {
                    "date": "2026-03-30T13:22:15.600268Z",
                    "number": "39",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-31T00:38:31.653120Z",
                    "number": "40",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (4).| Product Remediations created (4).| Product Identifiers created (13).| Product Identifiers removed (13).| References created (47).| CWES updated (1)."
                },
                {
                    "date": "2026-03-31T00:38:38.571189Z",
                    "number": "41",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-31T11:05:45.417176Z",
                    "number": "42",
                    "summary": "References created (2)."
                },
                {
                    "date": "2026-04-01T11:41:42.208245Z",
                    "number": "43",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-04-02T00:32:41.461907Z",
                    "number": "44",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (4).| Product Remediations created (4).| Product Identifiers created (13).| Product Identifiers removed (13).| References created (47).| CWES updated (1)."
                },
                {
                    "date": "2026-04-02T12:19:10.839324Z",
                    "number": "45",
                    "summary": "References created (5)."
                },
                {
                    "date": "2026-04-02T12:19:14.400150Z",
                    "number": "46",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "46"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1295663",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Debian Linux"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/140.9.0esr-1~deb12u1",
                                        "product": {
                                            "name": "vers:deb/140.9.0esr-1~deb12u1",
                                            "product_id": "CSAFPID-5913138",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/debian/firefox-esr@140.9.0esr-1~deb12u1?distro=bookworm"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "firefox-esr"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/1:140.9.0esr-1~deb12u1",
                                        "product": {
                                            "name": "vers:deb/1:140.9.0esr-1~deb12u1",
                                            "product_id": "CSAFPID-5920681",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/debian/thunderbird@1:140.9.0esr-1~deb12u1?distro=bookworm"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "thunderbird"
                            }
                        ],
                        "category": "product_family",
                        "name": "bookworm"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/140.9.0esr-1~deb11u1",
                                        "product": {
                                            "name": "vers:deb/140.9.0esr-1~deb11u1",
                                            "product_id": "CSAFPID-5920680",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/debian/firefox-esr@140.9.0esr-1~deb11u1?distro=bullseye"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "firefox-esr"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/1:140.9.0esr-1~deb11u1",
                                        "product": {
                                            "name": "vers:deb/1:140.9.0esr-1~deb11u1",
                                            "product_id": "CSAFPID-5920682",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/debian/thunderbird@1:140.9.0esr-1~deb11u1?distro=bullseye"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "thunderbird"
                            }
                        ],
                        "category": "product_family",
                        "name": "bullseye"
                    }
                ],
                "category": "vendor",
                "name": "Debian"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/149",
                                "product": {
                                    "name": "vers:unknown/149",
                                    "product_id": "CSAFPID-5902760"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<149",
                                "product": {
                                    "name": "vers:unknown/<149",
                                    "product_id": "CSAFPID-5906272"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unspecified|<149",
                                "product": {
                                    "name": "vers:unknown/unspecified|<149",
                                    "product_id": "CSAFPID-5902330"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Firefox"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/115.34",
                                "product": {
                                    "name": "vers:unknown/115.34",
                                    "product_id": "CSAFPID-5902762"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/140.9",
                                "product": {
                                    "name": "vers:unknown/140.9",
                                    "product_id": "CSAFPID-5902754"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<115.34",
                                "product": {
                                    "name": "vers:unknown/<115.34",
                                    "product_id": "CSAFPID-5906270"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<140.9",
                                "product": {
                                    "name": "vers:unknown/<140.9",
                                    "product_id": "CSAFPID-5906271"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unspecified|<115.34",
                                "product": {
                                    "name": "vers:unknown/unspecified|<115.34",
                                    "product_id": "CSAFPID-5902340"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unspecified|<140.9",
                                "product": {
                                    "name": "vers:unknown/unspecified|<140.9",
                                    "product_id": "CSAFPID-5902331"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Firefox ESR"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/140.9",
                                "product": {
                                    "name": "vers:unknown/140.9",
                                    "product_id": "CSAFPID-5903172"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/149",
                                "product": {
                                    "name": "vers:unknown/149",
                                    "product_id": "CSAFPID-5902761"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<149",
                                "product": {
                                    "name": "vers:unknown/<149",
                                    "product_id": "CSAFPID-5906268"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/esr <140.9",
                                "product": {
                                    "name": "vers:unknown/esr <140.9",
                                    "product_id": "CSAFPID-5906269"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unspecified|<140.9",
                                "product": {
                                    "name": "vers:unknown/unspecified|<140.9",
                                    "product_id": "CSAFPID-5902808"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unspecified|<149",
                                "product": {
                                    "name": "vers:unknown/unspecified|<149",
                                    "product_id": "CSAFPID-5902807"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Thunderbird"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<115.34.0",
                                "product": {
                                    "name": "vers:unknown/<115.34.0",
                                    "product_id": "CSAFPID-5902500",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<149.0",
                                "product": {
                                    "name": "vers:unknown/<149.0",
                                    "product_id": "CSAFPID-5902501",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=128.0|<140.9.0",
                                "product": {
                                    "name": "vers:unknown/>=128.0|<140.9.0",
                                    "product_id": "CSAFPID-5902502",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "firefox"
                    }
                ],
                "category": "vendor",
                "name": "Mozilla"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1317177",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:oracle:linux:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Oracle Linux"
                    }
                ],
                "category": "vendor",
                "name": "Oracle"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1317175",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1",
                                        "product": {
                                            "name": "vers:rpm/10.1",
                                            "product_id": "CSAFPID-5180289",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/o:redhat:enterprise_linux:10.1"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat Enterprise Linux AppStream (v. 10)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/8",
                                        "product": {
                                            "name": "vers:rpm/8",
                                            "product_id": "CSAFPID-1432908",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:enterprise_linux:8::appstream"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat Enterprise Linux AppStream (v. 8)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/9",
                                        "product": {
                                            "name": "vers:rpm/9",
                                            "product_id": "CSAFPID-1432758",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:enterprise_linux:9::appstream"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat Enterprise Linux AppStream (v. 9)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el10_1",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el10_1",
                                            "product_id": "CSAFPID-5920619",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/firefox@140.9.0-1.el10_1?arch=x86_64"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el8_10",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el8_10",
                                            "product_id": "CSAFPID-5920626",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/firefox@140.9.0-1.el8_10?arch=x86_64"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el9_7",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el9_7",
                                            "product_id": "CSAFPID-5920622",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/firefox@140.9.0-1.el9_7?arch=x86_64"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "firefox"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el10_1",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el10_1",
                                            "product_id": "CSAFPID-5920620",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/firefox-debuginfo@140.9.0-1.el10_1?arch=x86_64"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el8_10",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el8_10",
                                            "product_id": "CSAFPID-5920627",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/firefox-debuginfo@140.9.0-1.el8_10?arch=x86_64"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el9_7",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el9_7",
                                            "product_id": "CSAFPID-5920623",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/firefox-debuginfo@140.9.0-1.el9_7?arch=x86_64"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "firefox-debuginfo"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el10_1",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el10_1",
                                            "product_id": "CSAFPID-5920621",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/firefox-debugsource@140.9.0-1.el10_1?arch=x86_64"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el8_10",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el8_10",
                                            "product_id": "CSAFPID-5920628",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/firefox-debugsource@140.9.0-1.el8_10?arch=x86_64"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el9_7",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el9_7",
                                            "product_id": "CSAFPID-5920624",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/firefox-debugsource@140.9.0-1.el9_7?arch=x86_64"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "firefox-debugsource"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el9_7",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el9_7",
                                            "product_id": "CSAFPID-5920625",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/firefox-x11@140.9.0-1.el9_7?arch=x86_64"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "firefox-x11"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el10_1",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el10_1",
                                            "product_id": "CSAFPID-5983402",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/thunderbird@140.9.0-1.el10_1?arch=x86_64"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el9_7",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el9_7",
                                            "product_id": "CSAFPID-5966237",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/thunderbird@140.9.0-1.el9_7?arch=x86_64"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "thunderbird"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el10_1",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el10_1",
                                            "product_id": "CSAFPID-5983403",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/thunderbird-debuginfo@140.9.0-1.el10_1?arch=x86_64"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el9_7",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el9_7",
                                            "product_id": "CSAFPID-5966238",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/thunderbird-debuginfo@140.9.0-1.el9_7?arch=x86_64"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "thunderbird-debuginfo"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el10_1",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el10_1",
                                            "product_id": "CSAFPID-5983404",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/thunderbird-debugsource@140.9.0-1.el10_1?arch=x86_64"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/140.9.0-1.el9_7",
                                        "product": {
                                            "name": "vers:rpm/140.9.0-1.el9_7",
                                            "product_id": "CSAFPID-5966239",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/thunderbird-debugsource@140.9.0-1.el9_7?arch=x86_64"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "thunderbird-debugsource"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1317176",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:suse:opensuse:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "SUSE openSUSE"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1317174",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:suse:suse_linux:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "SuSE Linux"
                    }
                ],
                "category": "vendor",
                "name": "SUSE"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-4686",
            "cwe": {
                "id": "CWE-754",
                "name": "Improper Check for Unusual or Exceptional Conditions"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "Incorrect boundary conditions in the Graphics: Canvas2D component",
                    "title": "mozilla - https://www.mozilla.org/en-US/security/advisories/mfsa2026-22/"
                },
                {
                    "category": "description",
                    "text": "Incorrect boundary conditions in the Graphics: Canvas2D component",
                    "title": "mozilla - https://www.mozilla.org/en-US/security/advisories/mfsa2026-21/"
                },
                {
                    "category": "description",
                    "text": "Incorrect boundary conditions in the Graphics: Canvas2D component",
                    "title": "mozilla - https://www.mozilla.org/en-US/security/advisories/mfsa2026-20/"
                },
                {
                    "category": "description",
                    "text": "Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/4xxx/CVE-2026-4686.json"
                },
                {
                    "category": "description",
                    "text": "Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-4686"
                },
                {
                    "category": "description",
                    "text": "Incorrect boundary conditions in the Graphics: Canvas2D component",
                    "title": "mozilla - https://www.mozilla.org/en-US/security/advisories/mfsa2026-23/"
                },
                {
                    "category": "description",
                    "text": "Incorrect boundary conditions in the Graphics: Canvas2D component",
                    "title": "mozilla - https://www.mozilla.org/en-US/security/advisories/mfsa2026-24/"
                },
                {
                    "category": "description",
                    "text": "Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-4686"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nIncorrect boundary conditions in the Graphics: Canvas2D component",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:5931.json"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nIncorrect boundary conditions in the Graphics: Canvas2D component",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:5930.json"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nIncorrect boundary conditions in the Graphics: Canvas2D component",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:5932.json"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nIncorrect boundary conditions in the Graphics: Canvas2D component",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:6188.json"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nIncorrect boundary conditions in the Graphics: Canvas2D component",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:6342.json"
                },
                {
                    "category": "other",
                    "text": "0.00018",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "5.6",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is product data available from source Certbundde, VENDOR FIX as product remediation category",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent EPSS score",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 3\n",
                    "title": "Vendor assessment"
                },
                {
                    "category": "details",
                    "text": "Severity: 3\n",
                    "title": "Vendor assessment"
                },
                {
                    "category": "details",
                    "text": "Severity: 3\n",
                    "title": "Vendor assessment"
                },
                {
                    "category": "details",
                    "text": "Severity: 3\n",
                    "title": "Vendor assessment"
                },
                {
                    "category": "details",
                    "text": "Severity: 3\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "first_fixed": [
                    "CSAFPID-5913138",
                    "CSAFPID-5920680",
                    "CSAFPID-5920681",
                    "CSAFPID-5920682"
                ],
                "fixed": [
                    "CSAFPID-5902754",
                    "CSAFPID-5902762",
                    "CSAFPID-5902760",
                    "CSAFPID-5902761",
                    "CSAFPID-5903172",
                    "CSAFPID-5920619",
                    "CSAFPID-5920620",
                    "CSAFPID-5920621",
                    "CSAFPID-5920622",
                    "CSAFPID-5920623",
                    "CSAFPID-5920624",
                    "CSAFPID-5920625",
                    "CSAFPID-5920626",
                    "CSAFPID-5920627",
                    "CSAFPID-5920628",
                    "CSAFPID-5966237",
                    "CSAFPID-5966238",
                    "CSAFPID-5966239",
                    "CSAFPID-5983402",
                    "CSAFPID-5983403",
                    "CSAFPID-5983404"
                ],
                "known_affected": [
                    "CSAFPID-5902330",
                    "CSAFPID-5902331",
                    "CSAFPID-5902340",
                    "CSAFPID-5902500",
                    "CSAFPID-5902501",
                    "CSAFPID-5902502",
                    "CSAFPID-5902807",
                    "CSAFPID-5902808",
                    "CSAFPID-5906268",
                    "CSAFPID-5906269",
                    "CSAFPID-5906270",
                    "CSAFPID-5906271",
                    "CSAFPID-5906272",
                    "CSAFPID-1295663",
                    "CSAFPID-1317176",
                    "CSAFPID-1317175",
                    "CSAFPID-1317174",
                    "CSAFPID-1317177"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/4xxx/CVE-2026-4686.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-4686"
                },
                {
                    "category": "external",
                    "summary": "Source - mozilla",
                    "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-22/"
                },
                {
                    "category": "external",
                    "summary": "Source - mozilla",
                    "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-21/"
                },
                {
                    "category": "external",
                    "summary": "Source - mozilla",
                    "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-20/"
                },
                {
                    "category": "external",
                    "summary": "Source - mozilla",
                    "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-23/"
                },
                {
                    "category": "external",
                    "summary": "Source - mozilla",
                    "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-24/"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-4686"
                },
                {
                    "category": "external",
                    "summary": "Source - hkcert",
                    "url": "https://www.hkcert.org/security-bulletin/mozilla-products-multiple-vulnerabilities_20260325"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0850.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:5931.json"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:5930.json"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:5932.json"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:6188.json"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:6342.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; mozilla; nvd",
                    "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2016351"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://www.mozilla.org/security/advisories/mfsa2026-20/"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://www.mozilla.org/security/advisories/mfsa2026-21/"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://www.mozilla.org/security/advisories/mfsa2026-22/"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://www.mozilla.org/security/advisories/mfsa2026-23/"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://www.mozilla.org/security/advisories/mfsa2026-24/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0850.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0850"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-20/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-21/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-22/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-23/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-24/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Y7M6NU74R4Q7BLCQHUTUH3DFSFTPCPKT/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.debian.org/debian-security-announce/2026/msg00087.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-4686"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450734"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-4686"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4686"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.mozilla.org/security/advisories/mfsa2026-22/#CVE-2026-4686"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.mozilla.org/security/advisories/mfsa2026-24/#CVE-2026-4686"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:5931"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/updates/classification/#important"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450710"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450711"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450712"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450713"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450714"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450715"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450718"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450719"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450720"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450721"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450722"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450723"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450724"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450725"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450726"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450727"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450728"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450729"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450730"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450732"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450733"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450735"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450738"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450739"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450740"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450741"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450742"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450744"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450746"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450747"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450748"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450751"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450752"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450755"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450756"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450757"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5931.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:5930"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5930.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:5932"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5932.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.debian.org/debian-security-announce/2026/msg00088.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.debian.org/debian-lts-announce/2026/03/msg00014.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.debian.org/debian-lts-announce/2026/03/msg00015.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.suse.com/pipermail/sle-security-updates/2026-March/025023.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.suse.com/pipermail/sle-security-updates/2026-March/025022.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://linux.oracle.com/errata/ELSA-2026-5930.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://linux.oracle.com/errata/ELSA-2026-5931.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://linux.oracle.com/errata/ELSA-2026-5932.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:6188"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451001"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451006"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_6188.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://linux.oracle.com/errata/ELSA-2026-6188.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ELMKS2KLVJGOTFRHFX4CFYYGKJCR3ZFX/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:6342"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_6342.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://linux.oracle.com/errata/ELSA-2026-6342.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.suse.com/pipermail/sle-security-updates/2026-April/025116.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YYCV757JWWKCAIP63ZNZ7UWNGGZJPRIV/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "http://linux.oracle.com/errata/ELSA-2026-6342.html"
                }
            ],
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
                    "product_ids": [
                        "CSAFPID-5180289",
                        "CSAFPID-5920619",
                        "CSAFPID-5920620",
                        "CSAFPID-5920621"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:5931"
                },
                {
                    "category": "vendor_fix",
                    "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
                    "product_ids": [
                        "CSAFPID-1432758",
                        "CSAFPID-5920622",
                        "CSAFPID-5920623",
                        "CSAFPID-5920624",
                        "CSAFPID-5920625"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:5930"
                },
                {
                    "category": "vendor_fix",
                    "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
                    "product_ids": [
                        "CSAFPID-1432908",
                        "CSAFPID-5920626",
                        "CSAFPID-5920627",
                        "CSAFPID-5920628"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:5932"
                },
                {
                    "category": "vendor_fix",
                    "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
                    "product_ids": [
                        "CSAFPID-1432758",
                        "CSAFPID-5966237",
                        "CSAFPID-5966238",
                        "CSAFPID-5966239"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:6188"
                },
                {
                    "category": "vendor_fix",
                    "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
                    "product_ids": [
                        "CSAFPID-5180289",
                        "CSAFPID-5983402",
                        "CSAFPID-5983403",
                        "CSAFPID-5983404"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:6342"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1295663",
                        "CSAFPID-1317174",
                        "CSAFPID-1317175",
                        "CSAFPID-1317176",
                        "CSAFPID-1317177",
                        "CSAFPID-5902330",
                        "CSAFPID-5902331",
                        "CSAFPID-5902340",
                        "CSAFPID-5902500",
                        "CSAFPID-5902501",
                        "CSAFPID-5902502",
                        "CSAFPID-5902807",
                        "CSAFPID-5902808",
                        "CSAFPID-5906268",
                        "CSAFPID-5906269",
                        "CSAFPID-5906270",
                        "CSAFPID-5906271",
                        "CSAFPID-5906272"
                    ]
                }
            ],
            "title": "CVE-2026-4686"
        }
    ]
}