Mozilla · Thunderbird · CVE-2026-84642
**Name of the Vulnerable Software and Affected Versions**
Thunderbird versions prior to 153.2
Thunderbird versions prior to 155
**Description**
The `mail.allowed attachment hostnames` advanced configuration setting is used in a regular expression without proper escaping. This flaw allows certain unintended hostnames to match the expression, potentially enabling the serving of remote attachments from unauthorized hosts.
**Recommendations**
Update Thunderbird to version 153.2 or later.
Update Thunderbird to version 155 or later.