← back
CVE-2026-92238criticalCWE-444

Ambiguous parsing of mail headers

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 0.6%
exploitation probability
0.6%top 54% of all CVEs
observed exploitation
nono source reports it
A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Mozilla · Thunderbird