Thunderbird Uninitialized Memory Use in MIME Bodies (before 155)
CVE-2026-84639 Published on September 1, 2026
Uninitialized memory in MIME parsing
Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Products Associated with CVE-2026-84639
Want to know whenever a new CVE is published for Mozilla Thunderbird? stack.watch will email you.
Affected Versions
Mozilla Thunderbird:- Version 140.15, <= 140.* is unaffected.
- Version 153.2, <= 153.* is unaffected.
- Version 155, <= * is unaffected.