Heap Buffer Overflow in Thunderbird by Mozilla
CVE-2026-103500

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
30 September 2026

What is CVE-2026-103500?

A heap buffer overflow vulnerability exists in Mozilla Thunderbird, which can be exploited by triggering a user to open an unusually large email, specifically one that is 2GB or larger. This flaw can lead to potential arbitrary code execution, compromising the security and integrity of the user’s system. The vulnerability has been addressed in updates 157, 140.17, and 153.4 of Thunderbird, emphasizing the importance of keeping applications updated to mitigate security risks.

Affected Version(s)

Thunderbird 140.17

Thunderbird 153.4

Thunderbird 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ahmed Albalawi
.