@d-pupp The list of package versions that include the fix is in https://security-tracker.debian.org/tra ... -2024-9680. Debian packages are patched with extra security fixes, you should look at Debian's CVE tracker and not Mozilla's security advisories page.
EDIT: you're right, not fixed in trixie yet. It's not uncommon for testing to receive bug fixes after both unstable and stable. The former gets the newest packages and they tend to carry security fixes that haven't been backported yet, and the latter receives security fixes regularly.