VDB
TNCVE-2026-4371
TNCVE-2026-4371
PUBLISHED
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.
Timeline
- Mar 24, 2026 CVE Published
References
- Tenable: CVE-2026-4371 advisory