Junglewise Threat Intelligence

CVE-2026-84640: Mozilla Thunderbird one-byte buffer read overflow in mail parser

CVE-2026-84640 · Severity: high · CVSS 7.5 · Published 2026-09-01

Executive brief

Thunderbird is an email client used by millions to read and manage email messages. A maliciously crafted email header can trigger a one-byte read past the end of a buffer, potentially allowing an attacker to access sensitive memory contents or crash the application when processing the malicious email.

Technical details

A one-byte out-of-bounds read vulnerability exists in Thunderbird's mail header parsing logic. The vulnerability is triggered when processing a maliciously constructed mail header that causes the parser to read one byte beyond the allocated buffer boundary. The attack vector is network-based (via receipt of a malicious email), though no user interaction beyond opening an email is required. An attacker can potentially leak sensitive memory contents or trigger an information disclosure. The vulnerability has been fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Affected products

  • Mozilla Thunderbird before 155, before 140.15, before 153.2

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Fixed in Thunderbird 155, 140.15, and 153.2

References

Related threats