A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVSS
No CVSS.
References
Configurations
No configuration.
History
16 Sep 2026, 15:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary | (en) A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. |
Information
Published : 2026-09-15 20:19
Updated : 2026-09-16 19:34
NVD link : CVE-2026-92240
Mitre link : CVE-2026-92240
CVE.ORG link : CVE-2026-92240
JSON object : View
Products Affected
No product.
CWE
No CWE.
