Mozilla Foundation Security Advisory 2026-95

Security Vulnerabilities fixed in Thunderbird 140.16

Announced
September 15, 2026
Impact
high
Products
Thunderbird
Fixed in
  • Thunderbird 140.16

In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts. Note: We have changed how we publish advisories. We no longer roll all internally identified memory safety vulnerabilities into a single CVE and are now issuing an advisory for every individual bug.

#CVE-2026-92238: Ambiguous parsing of mail headers

Reporter
Ramesh Adhikari, Dr. Faruk Kazi (CoE-CNDS Lab, VJTI, Mumbai, India)
Impact
medium
Description

A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations.

References

#CVE-2026-92239: Buffer overrun in IMAP

Reporter
Ramesh Adhikari, Dr. Faruk Kazi (CoE-CNDS Lab, VJTI, Mumbai, India)
Impact
medium
Description

A maliciously constructed IMAP line could cause an out-of-bounds buffer read.

References

#CVE-2026-92240: Out-of-bounds read in IMAP response parser

Reporter
Ahmed Albalawi
Impact
low
Description

A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication.

References

#CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component

Reporter
devdharan9424@gmail.com
Impact
high
References

#CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92014: Privilege escalation due to incorrect boundary conditions in the Graphics component

Reporter
Jacolon Walker
Impact
high
References

#CVE-2026-92015: Privilege escalation in the WebExtensions component

Reporter
Quy Pham
Impact
high
References

#CVE-2026-92016: Use-after-free in the Disability Access APIs component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92017: Privilege escalation in the DOM: Service Workers component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component

Reporter
Quy Pham
Impact
high
References

#CVE-2026-92019: Mitigation bypass in the Remote Settings Client component

Reporter
Shu Takahashi
Impact
high
References

#CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component

Reporter
Rintaro Kawasugi
Impact
high
References

#CVE-2026-92021: Use-after-free in the JavaScript Engine: JIT component

Reporter
Tomer Fichman
Impact
high
References

#CVE-2026-92022: Use-after-free in the DOM: HTML Parser component

Reporter
Seohyeon Maeng
Impact
high
References

#CVE-2026-92023: Use-after-free in the XML component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92024: Use-after-free in the SVG component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92025: Use-after-free in the DOM: Navigation component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92026: Use-after-free in the Networking component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92027: Use-after-free in the DOM: Streams component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92028: Use-after-free in the DOM: Core & HTML component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92029: Use-after-free in the SVG component

Reporter
Mozilla
Impact
high
References

#CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component

Reporter
anas cherni
Impact
moderate
References

#CVE-2026-92031: Information disclosure in the Graphics: ImageLib component

Reporter
Qi Qin
Impact
moderate
References

#CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component

Reporter
Mozilla
Impact
moderate
References