CVE-2026-92240
Analyzed Analyzed - Analysis Complete

Out-of-Bounds Read in Thunderbird IMAP Parser

Vulnerability report for CVE-2026-92240, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-24

Assigner: Mozilla Corporation

Description

A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-24
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
mozilla thunderbird to 140.16.0 (exc)
mozilla thunderbird From 141.0 (inc) to 153.3.0 (exc)
mozilla thunderbird From 154.0 (inc) to 156.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a malicious or compromised IMAP server to crash Thunderbird by sending a specially crafted untagged 'ID' response. The issue occurs in the IMAP response parser before authentication, leading to an out-of-bounds read that causes the crash.

Detection Guidance

This vulnerability is specific to Thunderbird's IMAP response parser and cannot be directly detected via network commands. Monitor for Thunderbird crashes when connecting to IMAP servers. Check Thunderbird version with 'thunderbird --version' and compare against fixed versions (156 or 140.16).

If crashes occur during IMAP operations, especially with untagged '* ID' responses, this may indicate exploitation attempts.

Impact Analysis

If you use Thunderbird to connect to a malicious or compromised IMAP server, your application may crash unexpectedly. This could disrupt your email access and potentially lead to data loss if unsaved work is interrupted.

Compliance Impact

This vulnerability does not directly impact compliance with standards like GDPR or HIPAA as it involves a client-side crash due to an out-of-bounds read in an IMAP response parser. Compliance risks would only arise if the crash led to data exposure or processing errors, which is not indicated in the provided context.

Mitigation Strategies

Update Thunderbird to version 156 or 140.16 immediately. Disable IMAP connections temporarily if updates cannot be applied. Avoid connecting to untrusted IMAP servers until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92240. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart