Executive brief
Thunderbird is an email client used by millions to retrieve and manage email from IMAP servers. A malicious or compromised IMAP server can send a specially crafted line that causes Thunderbird to read memory beyond allocated buffer boundaries, potentially exposing sensitive data in memory or causing the application to crash.
Technical details
This is a buffer overrun vulnerability in Thunderbird's IMAP response parser. A maliciously constructed IMAP line causes an out-of-bounds buffer read, allowing an attacker-controlled or compromised IMAP server to trigger memory disclosure or denial of service. The attack requires network access to communicate with the client (IMAP protocol on network), but does not require prior authentication—a remote server can deliver the malicious response. The vulnerability is fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Affected products
- Mozilla Thunderbird versions prior to 140.16, 153.3, and 156
Timeline
- 2026-09-15: disclosed: Mozilla Security Advisory MFSA2026-94
- 2026-09-15: patched: Fixed in Thunderbird 156, 140.16, and 153.3