PT-2026-63484 · Mozilla+1 · Thunderbird+1

CVE-2026-14899

·

Published

2026-07-22

·

Updated

2026-08-12

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 153 Thunderbird versions prior to 140.13
Description An off-by-one error exists in the code used to parse MIME headers (Multipurpose Internet Mail Extensions) for display when forwarding a message, specifically when the setting to view all headers is enabled. This flaw allows a single byte to be read from memory beyond the header buffer, which can lead to an application crash.
Recommendations Update to version 153. Update to version 140.13.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:49621
ALSA-2026:49921
ALSA-2026:49922
CVE-2026-14899
OESA-2026-3195
OESA-2026-3196
OPENSUSE-SU-2026:11359-1
RHSA-2026:49621
RHSA-2026:49921
RHSA-2026:49922
RHSA-2026:53444
RHSA-2026:53445
RHSA-2026:53446
RHSA-2026:53453
RHSA-2026:53454
RHSA-2026:53455
RHSA-2026:53475
SUSE-SU-2026:3546-1

Affected Products

Rocky Linux
Thunderbird