CVE-2026-84640

Mozilla · Thunderbird

A buffer over-read vulnerability in Mozilla Thunderbird allows unauthenticated remote attackers to trigger a one byte memory read via a maliciously crafted mail header.

Executive summary

Mozilla Thunderbird is vulnerable to a memory buffer over-read flaw that could allow unauthenticated attackers to access sensitive memory contents.

Vulnerability

This vulnerability involves a buffer over-read condition triggered by a malformed mail header. The flaw is exploitable by an unauthenticated remote attacker who can send a specially crafted email to the target.

Business impact

The vulnerability carries a CVSS score of 7.5, reflecting a high severity due to the ease of remote, unauthenticated exploitation. Successful exploitation could lead to the unauthorized disclosure of sensitive information residing in memory, potentially exposing user credentials or private data.

Remediation

Immediate Action: Update Mozilla Thunderbird to version 140.15, 153.2, 155, or any later available release.

Proactive Monitoring: Review mail server and endpoint logs for anomalous header patterns or spikes in memory-related application errors.

Compensating Controls: While no direct virtual patch exists for this specific memory flaw, ensure that perimeter email security gateways are configured to strip or sanitize malformed mail headers before they reach the client.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for unauthorized information disclosure, organizations should prioritize updating all Thunderbird instances to the patched versions provided by Mozilla. Administrators must ensure that automated update mechanisms are active to minimize the window of exposure for end users.

More Mozilla CVEs

Sources

Originally found and disclosed by Ramesh Adhikari, Dr. Faruk Kazi (CoE-CNDS Lab, VJTI, Mumbai, India), per the CVE Program record.