Regex Flaw in Thunderbird Allows Unauthorized Attachment Serving
CVE-2026-84642
Currently unrated
What is CVE-2026-84642?
A vulnerability in Thunderbird arises from the insecure use of the mail.allowed_attachment_hostnames configuration setting within a regular expression. This oversight can potentially allow non-intended hostnames to match, thereby enabling unauthorized remote attachments to be served. The issue has been addressed in recent versions, ensuring heightened security against such attacks.
Affected Version(s)
Thunderbird 153.2
Thunderbird 155