Regex Flaw in Thunderbird Allows Unauthorized Attachment Serving
CVE-2026-84642

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
1 September 2026

What is CVE-2026-84642?

A vulnerability in Thunderbird arises from the insecure use of the mail.allowed_attachment_hostnames configuration setting within a regular expression. This oversight can potentially allow non-intended hostnames to match, thereby enabling unauthorized remote attachments to be served. The issue has been addressed in recent versions, ensuring heightened security against such attacks.

Affected Version(s)

Thunderbird 153.2

Thunderbird 155

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ChinhNguyen, Lowk3yz
.