Description
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A maliciously crafted mail header can trigger a one‑byte read past the end of a buffer in the Thunderbird mail parser. This over‑read could expose adjacent memory contents, potentially leaking sensitive data. The flaw does not provide a direct code execution path or denial of service, but may compromise confidentiality of header information or hidden data stored near the buffer.

Affected Systems

Mozilla’s Thunderbird email client is affected. The vulnerability is fixed in Thunderbird 155, 140.15, and 153.2, so any older installations of these releases are vulnerable.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not in the CISA KEV catalog, indicating no public exploitation data. The attack vector is inferred to be a malicious email sent to the client, as the flaw occurs during header parsing. While the impact is limited to data exposure, the lack of a severity assessment suggests a low‑to‑moderate risk. Applying the available fixes remains the recommended mitigation.

Generated by OpenCVE AI on September 1, 2026 at 23:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Thunderbird to version 155 (or at least 140.15 or 153.2) to apply the patch
  • If an update is not immediately possible, block or remove suspicious mail headers from untrusted senders before parsing
  • Configure your mail system to sanitize or strip malformed headers to avoid triggering the off‑by‑one read

Generated by OpenCVE AI on September 1, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla thunderbird
Vendors & Products Mozilla
Mozilla thunderbird

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Title One byte overflow read in mail parser
References

Subscriptions

Mozilla Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T21:44:15.623Z

Reserved: 2026-09-01T21:33:06.555Z

Link: CVE-2026-84640

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T22:17:19.800

Modified: 2026-09-01T22:17:19.800

Link: CVE-2026-84640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T23:45:17Z

Weaknesses

No weakness.