Junglewise Threat Intelligence

CVE-2026-92240: Mozilla Thunderbird out-of-bounds read in IMAP response parser

CVE-2026-92240 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Executive brief

Thunderbird is a popular email client used by millions for managing email accounts. A malicious or compromised IMAP email server can send a specially crafted response that crashes Thunderbird before the user even logs in, causing service disruption and denying access to email.

Technical details

This is an out-of-bounds read vulnerability in the IMAP response parser triggered by an untagged '* ID' response. The vulnerable code path is reachable before authentication, meaning an attacker controlling or intercepting an IMAP server connection can crash Thunderbird without requiring valid credentials. The vulnerability results in memory safety violations that cause a denial of service. Mozilla patched this issue in Thunderbird 156, 140.16, and 153.3.

Affected products

  • Mozilla Thunderbird before 140.16, 153.3, and 156

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Thunderbird 156, 140.16, and 153.3

References

Related threats