Mail Header Parsing Issues in Thunderbird by Mozilla
CVE-2026-92238

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
15 September 2026

What is CVE-2026-92238?

A crafted mail header in Thunderbird can cause multiple fields to be incorrectly parsed as a single field, potentially leading to parsing errors or memory safety violations. This issue undermines the integrity of the email handling process, making it critical for users to ensure they have updated to Thunderbird version 140.16 or later to mitigate this risk.

Affected Version(s)

Thunderbird 140.16

Thunderbird 156

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ramesh Adhikari, Dr. Faruk Kazi (CoE-CNDS Lab, VJTI, Mumbai, India)
.