CVE-2026-84640
Mozilla · Thunderbird
A buffer over-read vulnerability in Mozilla Thunderbird allows unauthenticated remote attackers to trigger a one byte memory read via a maliciously crafted mail header.
Executive summary
Mozilla Thunderbird is vulnerable to a memory buffer over-read flaw that could allow unauthenticated attackers to access sensitive memory contents.
Vulnerability
This vulnerability involves a buffer over-read condition triggered by a malformed mail header. The flaw is exploitable by an unauthenticated remote attacker who can send a specially crafted email to the target.
Business impact
The vulnerability carries a CVSS score of 7.5, reflecting a high severity due to the ease of remote, unauthenticated exploitation. Successful exploitation could lead to the unauthorized disclosure of sensitive information residing in memory, potentially exposing user credentials or private data.
Remediation
Immediate Action: Update Mozilla Thunderbird to version 140.15, 153.2, 155, or any later available release.
Proactive Monitoring: Review mail server and endpoint logs for anomalous header patterns or spikes in memory-related application errors.
Compensating Controls: While no direct virtual patch exists for this specific memory flaw, ensure that perimeter email security gateways are configured to strip or sanitize malformed mail headers before they reach the client.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for unauthorized information disclosure, organizations should prioritize updating all Thunderbird instances to the patched versions provided by Mozilla. Administrators must ensure that automated update mechanisms are active to minimize the window of exposure for end users.
More Mozilla CVEs
Sources
Originally found and disclosed by Ramesh Adhikari, Dr. Faruk Kazi (CoE-CNDS Lab, VJTI, Mumbai, India), per the CVE Program record.