CVE-2026-92238

Summary

A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.

Affected Software

VendorProductVersion RangeStatus
MozillaThunderbird140.16 <= 140.*unaffected
MozillaThunderbird156 <= *unaffected

Weaknesses

References