Mozilla Foundation Security Advisory 2026-88
Security Vulnerabilities fixed in Thunderbird 153.2
- Announced
- September 1, 2026
- Impact
- high
- Products
- Thunderbird
- Fixed in
-
- Thunderbird 153.2
In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.
#CVE-2026-84639: Uninitialized memory in MIME parsing
- Reporter
- Ramesh Adhikari, Dr. Faruk Kazi (CoE-CNDS Lab, VJTI, Mumbai, India)
- Impact
- high
Description
Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used.
References
#CVE-2026-84640: One byte overflow read in mail parser
- Reporter
- Ramesh Adhikari, Dr. Faruk Kazi (CoE-CNDS Lab, VJTI, Mumbai, India)
- Impact
- medium
Description
A maliciously constructed mail header could lead to a one byte read past the end of a buffer.
References
#CVE-2026-84641: Information disclosure due to malicious IMAP server response
- Reporter
- ABDULAZIZ ALASAIQAH
- Impact
- low
Description
A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js.
References
#CVE-2026-84637: Calendar invitation attachments could launch local executables
- Reporter
- Trung Nguyen
- Impact
- low
Description
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename.
References
#CVE-2026-84642: Allowed UNC hostnames for attachments interpreted as a regular expression
- Reporter
- ChinhNguyen, Lowk3yz
- Impact
- low
Description
The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also match and serve remote attachments.
References
#CVE-2026-75874: Sandbox escape in the Remote Settings Client component
- Reporter
- crixer
- Impact
- high
References
#CVE-2026-84118: Use-after-free in the JavaScript: GC component
- Reporter
- x0e
- Impact
- high
References
#CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-84120: Use-after-free in the Audio/Video component
- Reporter
- Ukyo Akai
- Impact
- high
References
#CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-84122: Use-after-free in the Audio/Video component
- Reporter
- Hyeonjun Ahn
- Impact
- high
References
#CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-84124: Use-after-free in the DOM: Core & HTML component
- Reporter
- Hyeonjun Ahn
- Impact
- high
References
#CVE-2026-84125: Use-after-free in the DOM: Core & HTML component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-74952: Privilege escalation in the Application Update component
- Reporter
- Tomoya Nakanishi
- Impact
- moderate
References
#CVE-2026-84129: Site isolation issue in the DOM: Navigation component
- Reporter
- Yaqoub Aldurayhim
- Impact
- moderate
References
#CVE-2026-84130: Information disclosure in the Graphics: WebGPU component
- Reporter
- 5up3rh3i
- Impact
- moderate
References
#CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component
- Reporter
- navapon
- Impact
- moderate
References
#CVE-2026-84132: Information disclosure in the Networking: HTTP component
- Reporter
- Shu Takahashi
- Impact
- moderate
References
#CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component
- Reporter
- pakhunov.anton.n
- Impact
- low
References
#CVE-2026-84134: Other issue in the Profile Backup component
- Reporter
- 5up3rh3i
- Impact
- low
References
#CVE-2026-84136: Other issue in the DOM: Navigation component
- Reporter
- Apentota
- Impact
- low
References
#CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component
- Reporter
- Riski Muhammad Ivan
- Impact
- low
References
#CVE-2026-84139: Clickjacking issue in the DOM: Events component
- Reporter
- Long Nguyen
- Impact
- low
References
#CVE-2026-84140: Site isolation issue in the DOM: Navigation component
- Reporter
- Mohamed Mbarek
- Impact
- low
References
#CVE-2026-84141: Integer overflow in the Graphics: ImageLib component
- Reporter
- nguyentuanhung1149
- Impact
- low
References
#CVE-2026-84143: Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
- Reporter
- Jan de Mooij, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
- High Severity internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
- Moderate Severity internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
- Low Severity internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
#CVE-2026-84144: Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2
- Reporter
- Leo Tenenbaum, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
#CVE-2026-84145: Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
- Reporter
- Leo Tenenbaum, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
- High Severity internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
- Moderate Severity internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
- Low Severity internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15