Incorrect Message Encryption Display in Thunderbird by Mozilla
CVE-2025-26696
7HIGH
What is CVE-2025-26696?
A vulnerability exists in Thunderbird that allows crafted MIME email messages to be misrepresented as encrypted OpenPGP messages, whereas they actually contain an OpenPGP signed message. This flaw misleads users, potentially impacting the security context and trust in the email communications. It specifically affects versions of Thunderbird prior to 136 and 128.8, necessitating immediate attention from users to mitigate risks associated with deceptive message notifications.
Affected Version(s)
Thunderbird < 136
Thunderbird < 128.8