PT-2026-54447 · Mozilla · Thunderbird

·

CVE-2026-57962

·

Published

2026-07-01

·

Updated

2026-07-19

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 140.12.1 Thunderbird versions prior to 152.0.1
Description A malicious LDAP server can cause the Thunderbird LDAP client to crash due to memory exhaustion. This occurs when the client is configured to query the server for address-book autocomplete, allowing the server to stash arbitrarily large amounts of attacker-supplied data into the client.
Recommendations Update to version 140.12.1. Update to version 152.0.1.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57962
OESA-2026-2936
OESA-2026-3093
OPENSUSE-SU-2026:11164-1

Affected Products

Thunderbird