Mozilla Foundation Security Advisory 2025-91 Security Vulnerabilities Fixed in Thunderbird 140.5 Announced: November 12, 2025 Impact: High Product: Thunderbird Fixed in: Thunderbird 140.5 General Information: These flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts. Vulnerability List: CVE-2025-13012: Race condition in the Graphics component - Reporter: Irvan Kurniawan - Impact: High - References: Bug 1991458 CVE-2025-13016: Incorrect boundary conditions in the JavaScript: WebAssembly component - Reporter: Igor Morgenstern - Impact: High - References: Bug 1992130 CVE-2025-13017: Same-origin policy bypass in the DOM: Notifications component - Reporter: Mochammad Nosa Shandy Prastyo - Impact: Moderate - References: Bug 1980904 CVE-2025-13018: Mitigation bypass in the DOM: Security component - Reporter: Daniel Veditz - Impact: Moderate - References: Bug 1984940 CVE-2025-13019: Same-origin policy bypass in the DOM: Workers component - Reporter: Oskar L - Impact: Moderate - References: Bug 1988412 CVE-2025-13013: Mitigation bypass in the DOM: Core & HTML component - Reporter: Masato Kinugawa - Impact: Moderate - References: Bug 1991945 CVE-2025-13020: Use-after-free in the WebRTC: Audio/Video component - Reporter: Andreas Pehrson - Impact: Moderate - References: Bug 1995686 CVE-2025-13014: Use-after-free in the Audio/Video component - Reporter: Andrew Osmond - Impact: Moderate - References: Bug 1994241 CVE-2025-13015: Spoofing issue in Thunderbird - Reporter: Eemeli Aro - Impact: Low - References: Bug 1994164