VDB

DEBIAN-CVE-2026-0818

DEBIAN-CVE-2026-0818 PUBLISHED CVSS 4.300000190734863 MEDIUM

When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled with HTML and CSS, then the decrypted contents were rendered in a context in which the CSS styles from the outer messages were active. If the user had additionally allowed loading of the remote content referenced by the outer email message, and the email was crafted by the sender using a combination of CSS rules and fonts and animations, then it was possible to extract the secret contents of the email. This vulnerability was fixed in Thunderbird 147.0.1 and Thunderbird 140.7.1.

Risk Scores

CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
Debian:11thunderbird1:91.11.0-1, 1:91.11.0-1~deb11u1, 1:91.12.0-1~deb10u1
Debian:12thunderbird128.11.0, 1:102.11.0-1, 1:102.12.0-1~deb10u1
Debian:13thunderbird0, 1:128.13.0esr-1, 1:128.14.0esr-1
Debian:14thunderbird0, 1:128.13.0esr-1, 1:128.14.0esr-1

Timeline

  • Jan 28, 2026 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›