Description
A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Published: 2026-09-15
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-Bounds Read → Potential data exposure or denial of service
Action: Apply Patch
AI Analysis

Impact

A maliciously crafted IMAP line triggers an out‑of‑bounds read in Thunderbird’s IMAP parser. This flaw can expose parts of the process memory to a remote attacker or cause the client to crash, leading to service denial for the user. which falls under the CWE-811 classification Thunderbird installations running any version older than 140.16, 153.3, or 156 are susceptible.

Affected Systems

Mozilla Thunderbird for desktop; any version older than 140.16, 153.3, and 156 is susceptible.

Risk and Exploitability

Although the CVSS score is not publicly disclosed, the EPSS score of less than 1% suggests a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote adversary who can control Thunderbird malicious IMAP server.

Generated by OpenCVE AI on September 17, 2026 at 07:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Thunderbird to at least version 156, or to the fixed releases 140.16 or 153.3.
  • Limit IMAP connections to trusted servers and enforce strict authentication to reduce the attack surface.
  • Implement firewall or IDS rules that detect anomalous IMAP traffic, such as unusually long lines or repeated connection attempts, and block malicious traffic.
  • Disable or remove unused network protocols if they are not required for the user’s workflow, reducing potential exposure.

Generated by OpenCVE AI on September 17, 2026 at 07:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4782-1 thunderbird security update
Debian DSA Debian DSA DSA-6503-1 thunderbird security update
History

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Thu, 17 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-811

Wed, 16 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla thunderbird
Vendors & Products Mozilla
Mozilla thunderbird

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16. A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
References

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 140.16. A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.
References

Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 140.16.
Title Buffer overrun in IMAP
References

Subscriptions

Mozilla Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-16T14:24:29.124Z

Reserved: 2026-09-15T19:42:51.878Z

Link: CVE-2026-92239

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:19:41.577

Modified: 2026-09-16T19:34:05.910

Link: CVE-2026-92239

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T19:42:52Z

Links: CVE-2026-92239 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T07:45:17Z

Weaknesses