Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links
Published Jun 11, 2025
6.5
MEDIUMCVSS 3.1
EPSS 0.58%
Description
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability was fixed in Thunderbird 128.11.1 and Thunderbird 139.0.2.
Affected products
No data.
- < 128.11.1
- ≥ 135.0 · < 139.0.2
No data.
Red Hat Enterprise Linux 10
thunderbird-0:128.12.0-1.el10_0
Fixed · RHSA-2025:10195
Red Hat Enterprise Linux 8
thunderbird-0:128.12.0-1.el8_10
Fixed · RHSA-2025:10246
Red Hat Enterprise Linux 8.2 Advanced Update Support
thunderbird-0:128.12.0-1.el8_2
Fixed · RHSA-2025:10166
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
thunderbird-0:128.12.0-1.el8_4
Fixed · RHSA-2025:10165
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
thunderbird-0:128.12.0-1.el8_6
Fixed · RHSA-2025:10164
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
thunderbird-0:128.12.0-1.el8_6
Fixed · RHSA-2025:10164
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
thunderbird-0:128.12.0-1.el8_6
Fixed · RHSA-2025:10164
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
thunderbird-0:128.12.0-1.el8_8
Fixed · RHSA-2025:10163
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
thunderbird-0:128.12.0-1.el8_8
Fixed · RHSA-2025:10163
Red Hat Enterprise Linux 9
thunderbird-0:128.12.0-1.el9_6
Fixed · RHSA-2025:10196
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
thunderbird-0:128.12.0-1.el9_0
Fixed · RHSA-2025:10161
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
thunderbird-0:128.12.0-1.el9_2
Fixed · RHSA-2025:10160
Red Hat Enterprise Linux 9.4 Extended Update Support
thunderbird-0:128.12.0-1.el9_4
Fixed · RHSA-2025:10159
Red Hat Enterprise Linux 10
rhel10/thunderbird-flatpak
Affected
Red Hat Enterprise Linux 6
thunderbird
Out of support scope
Red Hat Enterprise Linux 7
thunderbird
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | thunderbird-0:128.12.0-1.el10_0 | Fixed | RHSA-2025:10195 |
| Red Hat Enterprise Linux 8 | thunderbird-0:128.12.0-1.el8_10 | Fixed | RHSA-2025:10246 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | thunderbird-0:128.12.0-1.el8_2 | Fixed | RHSA-2025:10166 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | thunderbird-0:128.12.0-1.el8_4 | Fixed | RHSA-2025:10165 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | thunderbird-0:128.12.0-1.el8_6 | Fixed | RHSA-2025:10164 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | thunderbird-0:128.12.0-1.el8_6 | Fixed | RHSA-2025:10164 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | thunderbird-0:128.12.0-1.el8_6 | Fixed | RHSA-2025:10164 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | thunderbird-0:128.12.0-1.el8_8 | Fixed | RHSA-2025:10163 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | thunderbird-0:128.12.0-1.el8_8 | Fixed | RHSA-2025:10163 |
| Red Hat Enterprise Linux 9 | thunderbird-0:128.12.0-1.el9_6 | Fixed | RHSA-2025:10196 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | thunderbird-0:128.12.0-1.el9_0 | Fixed | RHSA-2025:10161 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | thunderbird-0:128.12.0-1.el9_2 | Fixed | RHSA-2025:10160 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | thunderbird-0:128.12.0-1.el9_4 | Fixed | RHSA-2025:10159 |
| Red Hat Enterprise Linux 10 | rhel10/thunderbird-flatpak | Affected | n/a |
| Red Hat Enterprise Linux 6 | thunderbird | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | thunderbird | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jun 11, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2025-2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.58% (0.00580) | 45.76th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.47% (0.00466) | 36.54th | v5 (v2026.06.15) |
| Jun 12, 2025 | 0.04% (0.00037) | 10.39th | v4 (v2025.03.14) |
References (9)
- https://access.redhat.com/security/cve/CVE-2025-5986 Vendor Advisory
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1958580%2C1968012 Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=2372281 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2025/07/msg00002.html
- https://nvd.nist.gov/vuln/detail/CVE-2025-5986
- https://www.cve.org/CVERecord?id=CVE-2025-5986
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/#CVE-2025-5986
- https://www.mozilla.org/security/advisories/mfsa2025-49/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-50/ Vendor Advisory
Change history (0)
No recorded changes yet.