High · published September 2, 2026
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
| Product | Versions | Fixed in |
|---|---|---|
| mozilla/thunderbird | < 140.15.0 | 140.15.0 |
| mozilla/thunderbird | ≥ 141.0, < 153.2.0 | 153.2.0 |
| mozilla/thunderbird | ≥ 154.0, < 155.0 | 155.0 |