Memory Vulnerability in Mozilla Thunderbird by Mozilla
CVE-2026-84639

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
1 September 2026

What is CVE-2026-84639?

In specific scenarios involving certain MIME body formats, triggering an error condition can lead to the use of uninitialized memory within Mozilla Thunderbird. This behavior may potentially allow an attacker to exploit the vulnerability, leading to unpredictable application behavior or unauthorized access to sensitive information. The issue has been addressed in several versions of Thunderbird, ensuring that users are protected from this type of memory misuse.

Affected Version(s)

Thunderbird 140.15

Thunderbird 153.2

Thunderbird 155

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ramesh Adhikari, Dr. Faruk Kazi (CoE-CNDS Lab, VJTI, Mumbai, India)
.