CVE-2026-92238

A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.

Scoring

CVSS base score
0
EPSS probability
0.18%
Published
2026-09-15
Last modified
2026-09-16

Affected products

Markdown version · Browse all CVEs