CVE-2026-4371
Vulnerability Summary
Timeline
Description
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.
CVSS Metrics
- v3.1•HIGH•Score: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS Trends
Current EPSS score: 0.36%• Percentile: 28%
Techniques & Countermeasures
- CWE-126•Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
- CWE-130•Improper Handling of Length Parameter Inconsistency
The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.
Affected Systems
- mozilla•thunderbird
≥ unspecified, < 149 | ≥ unspecified, < 140.9 | < 140.9.0 | < 149.0
References (18)
- https://bugzilla.mozilla.org/show_bug.cgi?id=2023493
- https://www.mozilla.org/security/advisories/mfsa2026-23/
- https://www.mozilla.org/security/advisories/mfsa2026-24/
- https://access.redhat.com/security/cve/CVE-2026-4371
- https://bugzilla.redhat.com/show_bug.cgi?id=2451001
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4371.json
- https://access.redhat.com/errata/RHSA-2026:8315
- https://access.redhat.com/errata/RHSA-2026:6342
- https://access.redhat.com/errata/RHSA-2026:6917
- https://access.redhat.com/errata/RHSA-2026:8285
- https://access.redhat.com/errata/RHSA-2026:8850
- https://access.redhat.com/errata/RHSA-2026:8289
- https://access.redhat.com/errata/RHSA-2026:8288
- https://access.redhat.com/errata/RHSA-2026:8286
- https://access.redhat.com/errata/RHSA-2026:8287
- https://access.redhat.com/errata/RHSA-2026:8290
- https://access.redhat.com/errata/RHSA-2026:8284
- https://access.redhat.com/errata/RHSA-2026:6188