CVE-2026-84640CWE-126

CVE-2026-84640

High · published September 2, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
17.9
In the wild
Unconfirmed
What it is

A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00263 · 17.9th percentile
Weakness
CWE-126 · Buffer Over-read
Published
2026-09-02T02:17Z
Affected products (3)
ProductVersionsFixed in
mozilla/thunderbird< 140.15.0140.15.0
mozilla/thunderbird≥ 141.0, < 153.2.0153.2.0
mozilla/thunderbird≥ 154.0, < 155.0155.0
References (4)
EPSS history
Timeline
  • 03 SEP 03:32Z
    EPSS moved — → 0%
    epss
  • 01 SEP 21:33Z
    One byte overflow read in mail parser
    cvelistv5