Junglewise Threat Intelligence

CVE-2026-92239: Mozilla Thunderbird buffer overrun in IMAP response parsing

CVE-2026-92239 · Severity: high · CVSS 8.1 · Published 2026-09-15

Executive brief

Thunderbird is an email client used by millions to retrieve and manage email from IMAP servers. A malicious or compromised IMAP server can send a specially crafted line that causes Thunderbird to read memory beyond allocated buffer boundaries, potentially exposing sensitive data in memory or causing the application to crash.

Technical details

This is a buffer overrun vulnerability in Thunderbird's IMAP response parser. A maliciously constructed IMAP line causes an out-of-bounds buffer read, allowing an attacker-controlled or compromised IMAP server to trigger memory disclosure or denial of service. The attack requires network access to communicate with the client (IMAP protocol on network), but does not require prior authentication—a remote server can deliver the malicious response. The vulnerability is fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Affected products

  • Mozilla Thunderbird versions prior to 140.16, 153.3, and 156

Timeline

  • 2026-09-15: disclosed: Mozilla Security Advisory MFSA2026-94
  • 2026-09-15: patched: Fixed in Thunderbird 156, 140.16, and 153.3

References

Related threats