Out-of-Bounds Read Vulnerability in Thunderbird by Mozilla
CVE-2026-92240

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
15 September 2026

What is CVE-2026-92240?

An out-of-bounds read vulnerability exists in Mozilla Thunderbird due to a flawed IMAP response parser. A malicious IMAP server can exploit this vulnerability by sending an untagged '* ID' response, leading to a crash of the Thunderbird application. The parsing error occurs before user authentication, making it particularly concerning for users. This issue has been addressed in Thunderbird version 140.16 to enhance security and stability.

Affected Version(s)

Thunderbird 140.16

Thunderbird 156

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ahmed Albalawi
.