OOB buffer read in Thunderbird IMAP parser before 140.16
CVE-2026-92239 Published on September 15, 2026
Buffer overrun in IMAP
A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Products Associated with CVE-2026-92239
Want to know whenever a new CVE is published for Mozilla Thunderbird? stack.watch will email you.
Affected Versions
Mozilla Thunderbird:- Version 140.16, <= 140.* is unaffected.
- Version 153.3, <= 153.* is unaffected.
- Version 156, <= * is unaffected.