CVE-2026-14899
N/A
N/A
Summary
The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Mozilla | Thunderbird | 140.13 <= 140.* | unaffected |
| Mozilla | Thunderbird | 153 <= * | unaffected |
Weaknesses
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2046137
- https://www.mozilla.org/security/advisories/mfsa2026-71/
- https://www.mozilla.org/security/advisories/mfsa2026-72/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.