Back

HIGH

Information disclosure due to malicious IMAP server response

Published Sep 1, 2026

Description

A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Affected products

Remediation

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mozilla
Published Sep 1, 2026
Updated Sep 2, 2026
Reserved Sep 1, 2026

CISA Vulnrichment

Updated Sep 2, 2026

NVD

Status Analyzed
Modified Sep 3, 2026

Red Hat

Severity Low
Public date Sep 1, 2026
Bugzilla 2527115

ENISA EUVD

Assigner mozilla
Published Sep 1, 2026
Updated Sep 2, 2026

GitHub

No data