ZeroHour

CVE-2026-84639

mass

Uninitialized memory use in Mozilla Thunderbird MIME body handling

CVSS 3.1
9.1 critical
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-84639 is a use-of-uninitialized-memory flaw (CWE-457) in Mozilla Thunderbird's processing of MIME email bodies: when a specially crafted message triggers an error condition in certain MIME bodies, the client uses uninitialized memory. Per the published CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaw is rated as network-exploitable with low complexity and no privileges or user interaction required, consistent with an attacker simply delivering the crafted email to the victim's mailbox. The rated impact is high on confidentiality (potential disclosure of memory contents) and high on availability (potential crashes of the mail client), with no integrity impact. All Thunderbird users running releases older than the fixed builds (155, 153.2, and 140.15) are affected. There is no known exploitation in the wild, no public proof-of-concept, and EPSS assigns a low 0.3% probability of exploitation within 30 days.

What to do: Upgrade Thunderbird to 155, or to 153.2 or 140.15 on the respective older branches, as these are the versions where the flaw was fixed; no workarounds are documented in the available data, so patching is the primary mitigation. Since there is no known exploitation (EPSS 0.3%, not in CISA KEV, no public PoC), remediating within your normal patch cycle is reasonable, but prioritize shared or high-volume mail endpoints where untrusted email is automatically processed.

Affected
mozilla ThunderbirdAll releases prior to 155 (fixed in 155)
mozilla ThunderbirdAll releases prior to 153.2 (fixed in 153.2)
mozilla ThunderbirdAll releases prior to 140.15 (fixed in 140.15)
Estimated exposure
massseveral million desktop installs (Thunderbird's active user base is estimated in the millions; only unpatched versions are affected) — Mozilla does not publish exact install counts, but Thunderbird's active install base has long been estimated in the millions of users, so the affected population is plausibly millions of desktop clients, reduced to the subset still running…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Vendors
mozilla
Products
thunderbird
Weakness
CWE-457
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.