Junglewise Threat Intelligence

CVE-2026-57962: Mozilla Thunderbird memory exhaustion in LDAP address-book autocomplete

CVE-2026-57962 · Severity: info · CVSS 0 · Published 2026-07-01

Executive brief

Mozilla Thunderbird, a popular email client, is vulnerable to a denial-of-service attack when configured to use a malicious LDAP server for address-book autocompletion. An attacker controlling such a server can send excessive amounts of data to the user's computer, causing the application to consume all available memory and crash. This disrupts the user's ability to access their email and manage their contacts.

Technical details

A memory exhaustion vulnerability exists in the Thunderbird LDAP client component. When a user has configured an LDAP server for address-book autocomplete, a malicious or compromised server can respond to queries with an arbitrarily large volume of data. The client fails to properly bound or throttle this incoming data, leading to uncontrolled memory consumption. This eventually results in a denial-of-service (DoS) condition via a process crash. The issue is resolved in Thunderbird versions 152.0.1 and 140.12.1.

Affected products

  • Mozilla Thunderbird Fixed in 152.0.1 and 140.12.1

Timeline

  • 2026-06-30: advisory: Mozilla Foundation Security Advisory published
  • 2026-07-01: disclosed: CVE published to NVD

References

Related threats