CVE-2026-84640
massOne-Byte Buffer Over-Read in Mozilla Thunderbird Mail Header Parsing
CVE-2026-84640 is a buffer over-read (CWE-126) in Mozilla Thunderbird: a maliciously constructed mail header causes Thunderbird to read one byte past the end of a buffer while processing the message. An attacker triggers it by sending a specially crafted email whose header is mishandled during parsing, requiring no user interaction or credentials. The direct gain is limited disclosure of adjacent memory (Mozilla rates the confidentiality impact as high under CVSS, with no integrity or availability impact). All Thunderbird users running releases older than the fixed versions are potentially affected. There is no known public proof-of-concept, it is not in CISA KEV, and EPSS assigns a low 0.3% probability of exploitation in the next 30 days, so no exploitation is currently known.
What to do: Upgrade Thunderbird to version 155, or to 153.2 / 140.15 on the corresponding maintained branches currently in use. Verify the installed version via Help > About Thunderbird and apply the update promptly, since the flaw is remotely triggerable by an incoming message; no active exploitation or public PoC is known, so patching against future attack vectors is the priority. No workaround beyond upgrading is specified in the available data.
| mozilla thunderbird | Thunderbird releases prior to 155 on the current channel; the 153 series prior to 153.2; the 140 series prior to 140.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- thunderbird
- Weakness
- CWE-126
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.