Executive brief
Thunderbird is an email client used by millions to manage corporate and personal email. A specially crafted email header could cause the application to misparse multiple mail header fields as a single field, or trigger memory safety violations that could lead to a crash or data corruption.
Technical details
CVE-2026-92238 is an ambiguous parsing vulnerability in Thunderbird's mail header parsing logic. A maliciously constructed mail header can cause multiple fields to be incorrectly parsed as a single field, or trigger potential memory safety violations. The attack requires no authentication and can be delivered via email; however, the Mozilla advisory notes that scripting is disabled when reading mail in Thunderbird, which limits the impact compared to browser contexts. The vulnerability is fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Affected products
- Mozilla Thunderbird before 140.16, 153.3, or 156
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Thunderbird 156, 140.16, and 153.3