The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Aug 5, 2026 | Aug 4, 2026 |
| Debian | — | Upgrade thunderbird | Aug 9, 2026 | Aug 9, 2026 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 140.13Upgrade to the latest version of Mozilla Thunderbird | Jul 21, 2026 | Jul 21, 2026 |
| Redhat_linux | — | No solution existsUpgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsource | Jul 29, 2026 | Jul 22, 2026 |
| Rocky_linux | — | Upgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsource | Aug 7, 2026 | Aug 6, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub