CVE-2026-84639
massUninitialized memory use in Mozilla Thunderbird MIME body handling
CVE-2026-84639 is a use-of-uninitialized-memory flaw (CWE-457) in Mozilla Thunderbird's processing of MIME email bodies: when a specially crafted message triggers an error condition in certain MIME bodies, the client uses uninitialized memory. Per the published CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaw is rated as network-exploitable with low complexity and no privileges or user interaction required, consistent with an attacker simply delivering the crafted email to the victim's mailbox. The rated impact is high on confidentiality (potential disclosure of memory contents) and high on availability (potential crashes of the mail client), with no integrity impact. All Thunderbird users running releases older than the fixed builds (155, 153.2, and 140.15) are affected. There is no known exploitation in the wild, no public proof-of-concept, and EPSS assigns a low 0.3% probability of exploitation within 30 days.
What to do: Upgrade Thunderbird to 155, or to 153.2 or 140.15 on the respective older branches, as these are the versions where the flaw was fixed; no workarounds are documented in the available data, so patching is the primary mitigation. Since there is no known exploitation (EPSS 0.3%, not in CISA KEV, no public PoC), remediating within your normal patch cycle is reasonable, but prioritize shared or high-volume mail endpoints where untrusted email is automatically processed.
| mozilla Thunderbird | All releases prior to 155 (fixed in 155) |
| mozilla Thunderbird | All releases prior to 153.2 (fixed in 153.2) |
| mozilla Thunderbird | All releases prior to 140.15 (fixed in 140.15) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- thunderbird
- Weakness
- CWE-457
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.