Mozilla Foundation Security Advisory 2026-102
Security Vulnerabilities fixed in Thunderbird 140.17
- Announced
- September 30, 2026
- Impact
- high
- Products
- Thunderbird
- Fixed in
-
- Thunderbird 140.17
In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.
Note: We have changed how we publish advisories. We no longer roll all internally identified memory safety vulnerabilities into a single CVE and are now issuing an advisory for every individual bug.
#CVE-2026-103500: Heap buffer overflow opening large email
- Reporter
- Ahmed Albalawi <ahmedalbalawij@gmail.com>
- Impact
- low
Description
An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size.
References
#CVE-2026-100756: Incorrect boundary conditions in the Audio/Video: Playback component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100757: Use-after-free in the Widget component
- Reporter
- Mohamed Mbarek
- Impact
- high
References
#CVE-2026-100758: Sandbox escape in the DOM: Navigation component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100759: Uninitialized memory in the Storage: Quota Manager component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100762: Sandbox escape due to use-after-free in the DOM: Content Processes component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100766: Information disclosure in the Networking: JAR component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100767: Use-after-free in the Networking: Cache component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100769: Use-after-free in the JavaScript: WebAssembly component
- Reporter
- Tomer Fichman
- Impact
- high
References
#CVE-2026-100770: Sandbox escape due to use-after-free in the DOM: Content Processes component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100771: Undefined behavior in the DOM: Streams component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100772: Use-after-free in the DOM: Core & HTML component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100773: Use-after-free in the Storage: IndexedDB component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100774: Use-after-free in the DOM: Core & HTML component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100775: Sandbox escape in the Graphics component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100776: Use-after-free in the JavaScript: WebAssembly component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100777: Use-after-free in the Graphics: Canvas2D component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100778: Sandbox escape due to use-after-free in the DOM: Core & HTML component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100779: Use-after-free in the XSLT component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100780: Use-after-free in the DOM: Core & HTML component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100781: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100782: Privilege escalation due to incorrect boundary conditions in the Graphics component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100783: Uninitialized memory in the Audio/Video component
- Reporter
- 5up3rh3i
- Impact
- high
References
#CVE-2026-100784: Use-after-free in the Layout: Text and Fonts component
- Reporter
- 5up3rh3i
- Impact
- high
References
#CVE-2026-100785: Use-after-free in the DOM: Core & HTML component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100786: Sandbox escape due to use-after-free in the Graphics component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100788: Invalid pointer in the JavaScript: WebAssembly component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100789: Use-after-free in the Graphics: Canvas2D component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100790: Use-after-free in the XSLT component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100791: Use-after-free in the DOM: Core & HTML component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100832: Use-after-free in the Graphics: Canvas2D component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100792: JIT miscompilation in the JavaScript: WebAssembly component
- Reporter
- Amy Burnett of OpenAI
- Impact
- high
References
#CVE-2026-100794: Sandbox escape due to incorrect boundary conditions in the Internationalization component
- Reporter
- Mozilla
- Impact
- moderate
References
#CVE-2026-96869: Information disclosure in the Networking component
- Reporter
- Carlo Di Dato
- Impact
- moderate
References
#CVE-2026-100797: Privilege escalation due to use-after-free in the Graphics: WebRender component
- Reporter
- Mozilla
- Impact
- moderate
References
#CVE-2026-100801: Privilege escalation in the DLL Services component
- Reporter
- Mozilla
- Impact
- moderate
References
#CVE-2026-100803: Same-origin policy bypass in the WebExtensions component
- Reporter
- Yaqoub Aldurayhim
- Impact
- moderate
References
#CVE-2026-100807: Privilege escalation in the DOM: Service Workers component
- Reporter
- Khanh Nguyen
- Impact
- moderate
References
#CVE-2026-100811: Sandbox escape due to use-after-free in the DOM: Core & HTML component
- Reporter
- Yaqoub Aldurayhim
- Impact
- moderate
References
#CVE-2026-100818: Sandbox escape due to use-after-free in the Widget: Gtk component
- Reporter
- Mozilla
- Impact
- moderate
References
#CVE-2026-100819: Sandbox escape due to incorrect boundary conditions in the XPCOM component
- Reporter
- Mozilla
- Impact
- moderate
References
#CVE-2026-100820: Privilege escalation in the Address Bar component
- Reporter
- Tran Quac
- Impact
- moderate
References
#CVE-2026-100821: Site isolation issue in the Panning and Zooming component
- Reporter
- Nguyen Thanh Nguyen
- Impact
- moderate