Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Lowk3Yz

#36842of 56,330
7.5Total CVSS
Vulnerabilities · 1
PT-2026-84528
7.5
2026-09-01
Mozilla · Thunderbird · CVE-2026-84642
**Name of the Vulnerable Software and Affected Versions** Thunderbird versions prior to 153.2 Thunderbird versions prior to 155 **Description** The `mail.allowed attachment hostnames` advanced configuration setting is used in a regular expression without proper escaping. This flaw allows certain unintended hostnames to match the expression, potentially enabling the serving of remote attachments from unauthorized hosts. **Recommendations** Update Thunderbird to version 153.2 or later. Update Thunderbird to version 155 or later.