Off-by-One Error in MIME Header Parsing Affects Mozilla Thunderbird
CVE-2026-14899

7.5HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
22 July 2026

What is CVE-2026-14899?

An off-by-one error in the MIME header parsing code of Mozilla Thunderbird may allow an attacker to exploit a buffer overflow scenario. This issue occurs when the setting to view all headers is enabled, resulting in reading a single byte beyond the allocated buffer. This can lead to unexpected behavior, including potential application crashes. The vulnerability has been addressed in Thunderbird versions 153 and 140.13.

Affected Version(s)

Thunderbird 140.13

Thunderbird 153

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Claude, Kai Engert
.