ZeroHour

CVE-2026-84640

mass

One-Byte Buffer Over-Read in Mozilla Thunderbird Mail Header Parsing

CVSS 3.1
7.5 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-84640 is a buffer over-read (CWE-126) in Mozilla Thunderbird: a maliciously constructed mail header causes Thunderbird to read one byte past the end of a buffer while processing the message. An attacker triggers it by sending a specially crafted email whose header is mishandled during parsing, requiring no user interaction or credentials. The direct gain is limited disclosure of adjacent memory (Mozilla rates the confidentiality impact as high under CVSS, with no integrity or availability impact). All Thunderbird users running releases older than the fixed versions are potentially affected. There is no known public proof-of-concept, it is not in CISA KEV, and EPSS assigns a low 0.3% probability of exploitation in the next 30 days, so no exploitation is currently known.

What to do: Upgrade Thunderbird to version 155, or to 153.2 / 140.15 on the corresponding maintained branches currently in use. Verify the installed version via Help > About Thunderbird and apply the update promptly, since the flaw is remotely triggerable by an incoming message; no active exploitation or public PoC is known, so patching against future attack vectors is the priority. No workaround beyond upgrading is specified in the available data.

Affected
mozilla thunderbirdThunderbird releases prior to 155 on the current channel; the 153 series prior to 153.2; the 140 series prior to 140.15
Estimated exposure
masstens of millions of users (roughly 20-30 million monthly active Thunderbird desktop installs) — Thunderbird's publicly reported user base is on the order of tens of millions of monthly active users, and every desktop install that processes untrusted email is exposed until patched, although only a subset may be actively attacked.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Vendors
mozilla
Products
thunderbird
Weakness
CWE-126
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.