CVE-2026-92239: Vulnerability in Mozilla Thunderbird
A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.
AI Analysis
Technical Summary
This vulnerability involves an out-of-bounds buffer read triggered by a maliciously constructed IMAP line in Mozilla Thunderbird. The flaw could potentially lead to memory safety violations. Mozilla fixed this issue in Thunderbird 140.16. According to the vendor advisory, exploitation through email is unlikely because scripting is disabled when reading mail, but the risk exists in browser or browser-like contexts. The advisory is part of a broader set of memory safety fixes released simultaneously.
Potential Impact
The vulnerability could lead to memory safety violations via out-of-bounds buffer reads when processing IMAP lines. However, exploitation through normal email reading is mitigated by Thunderbird's disabled scripting in mail reading contexts. The impact is rated medium by the vendor.
Mitigation Recommendations
Users should update to Thunderbird version 140.16 or later, where this vulnerability has been fixed. No additional action is required if the software is already updated. The vendor manages remediation through this official fix.
CVE-2026-92239: Vulnerability in Mozilla Thunderbird
Description
A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.
Affected software
Mozilla
Thunderbird
pkg:github/mozilla/thunderbirdRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves an out-of-bounds buffer read triggered by a maliciously constructed IMAP line in Mozilla Thunderbird. The flaw could potentially lead to memory safety violations. Mozilla fixed this issue in Thunderbird 140.16. According to the vendor advisory, exploitation through email is unlikely because scripting is disabled when reading mail, but the risk exists in browser or browser-like contexts. The advisory is part of a broader set of memory safety fixes released simultaneously.
Potential Impact
The vulnerability could lead to memory safety violations via out-of-bounds buffer reads when processing IMAP lines. However, exploitation through normal email reading is mitigated by Thunderbird's disabled scripting in mail reading contexts. The impact is rated medium by the vendor.
Mitigation Recommendations
Users should update to Thunderbird version 140.16 or later, where this vulnerability has been fixed. No additional action is required if the software is already updated. The vendor manages remediation through this official fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mozilla
- Date Reserved
- 2026-09-15T19:42:51.878Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://www.mozilla.org/security/advisories/mfsa2026-95/","vendor":"Mozilla"}]
Threat ID: 6aa9a0bd55bf5e2cf54b8f0b
Added to database: 09/15/2026, 19:47:09 UTC
Last enriched: 09/15/2026, 20:02:29 UTC
Last updated: 09/16/2026, 03:17:48 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.