CVE-2026-4371

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*

History

No history.

Information

Published : 2026-03-24 21:16

Updated : 2026-03-27 18:05


NVD link : CVE-2026-4371

Mitre link : CVE-2026-4371

CVE.ORG link : CVE-2026-4371


JSON object : View

Products Affected

mozilla

  • thunderbird
CWE
CWE-126

Buffer Over-read