CVE-2026-92238
critical · 9.8A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
9.8
CVSS
0.6%
EPSS (exploit prob.)
46th
EPSS percentile
2026-09-15
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-444
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| mozilla | thunderbird | < 140.16.0 |
| mozilla | thunderbird | >= 141.0, < 153.3.0 |
| mozilla | thunderbird | >= 154.0, < 156.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-92238