← All CVEs

CVE-2026-92238

critical · 9.8

A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

9.8
CVSS
0.6%
EPSS (exploit prob.)
46th
EPSS percentile
2026-09-15
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-444

Affected products

VendorProductAffected versions
mozillathunderbird< 140.16.0
mozillathunderbird>= 141.0, < 153.3.0
mozillathunderbird>= 154.0, < 156.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-92238