PT-2026-63484 · Mozilla+1 · Thunderbird+1
CVE-2026-14899
·
Published
2026-07-22
·
Updated
2026-08-12
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Thunderbird versions prior to 153
Thunderbird versions prior to 140.13
Description
An off-by-one error exists in the code used to parse MIME headers (Multipurpose Internet Mail Extensions) for display when forwarding a message, specifically when the setting to view all headers is enabled. This flaw allows a single byte to be read from memory beyond the header buffer, which can lead to an application crash.
Recommendations
Update to version 153.
Update to version 140.13.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocky Linux
Thunderbird