CVE-2026-92238
Analyzed
Analyzed - Analysis Complete
Memory Corruption in Thunderbird via Malformed Mail Headers
Vulnerability report for CVE-2026-92238, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-15
Last updated on: 2026-09-24
Assigner: Mozilla Corporation
Description
Description
A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mozilla | thunderbird | to 140.16.0 (exc) |
| mozilla | thunderbird | From 141.0 (inc) to 153.3.0 (exc) |
| mozilla | thunderbird | From 154.0 (inc) to 156.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-444 | The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination. |