Incorrect Message Encryption Display in Thunderbird by Mozilla
CVE-2025-26696

7HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
10 March 2025

What is CVE-2025-26696?

A vulnerability exists in Thunderbird that allows crafted MIME email messages to be misrepresented as encrypted OpenPGP messages, whereas they actually contain an OpenPGP signed message. This flaw misleads users, potentially impacting the security context and trust in the email communications. It specifically affects versions of Thunderbird prior to 136 and 128.8, necessitating immediate attention from users to mitigate risks associated with deceptive message notifications.

Affected Version(s)

Thunderbird < 136

Thunderbird < 128.8

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcus Brinkmann
.
The Cyber Security Vulnerability Database.