First published: Tue Mar 04 2025(Updated: )
Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being encrypted.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <136<128.8 | |
Thunderbird | <136 | 136 |
Thunderbird | <128.8 | 128.8 |
Thunderbird | <128.8.0 | |
Thunderbird | >=129.0<136.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-26696 has been classified as a moderate severity vulnerability.
To fix CVE-2025-26696, users should upgrade to Thunderbird version 136 or later, or 128.8 or later.
CVE-2025-26696 may lead to users mistakenly believing that an OpenPGP signed message is encrypted, which could compromise the integrity of sensitive communications.
Thunderbird versions prior to 136 and prior to 128.8 are affected by CVE-2025-26696.
CVE-2025-26696 affects crafted MIME email messages that claim to contain encrypted OpenPGP messages.