CVE-2026-84640: One byte overflow read in mail parser
Published Sep 1, 2026
·Updated
A maliciously constructed mail header could lead to a one byte read past the end of a buffer.
Affected Software
4 affected componentsFixes available
Mozilla Thunderbird<155
Mozilla Thunderbird<155
155
Mozilla Thunderbird<140.15
140.15
Mozilla Thunderbird<153.2
153.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 155 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.2 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 155
Event History
Sep 1, 2026
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·09:33 PM
Data Sourced
via MITRE·09:33 PM
Description
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-84639
- CVE-2026-84640
- CVE-2026-84641
- CVE-2026-84642
- CVE-2026-84118
- CVE-2026-84119
- CVE-2026-84120
- CVE-2026-84121
- CVE-2026-84122
- CVE-2026-84123
- CVE-2026-84124
- CVE-2026-84125
- CVE-2026-84126
- CVE-2026-84128
- CVE-2026-84129
- CVE-2026-84130
- CVE-2026-84131
- CVE-2026-84132
- CVE-2026-84133
- CVE-2026-84134
- CVE-2026-84136
- CVE-2026-84137
- CVE-2026-84138
- CVE-2026-84139
- CVE-2026-84140
- CVE-2026-84141
- CVE-2026-84142
- CVE-2026-84143
- CVE-2026-84144
- CVE-2026-84145
- CVE-2026-75874
- CVE-2026-16365
- CVE-2026-16371
- CVE-2026-84637
- CVE-2026-74952
Frequently Asked Questions
1
Which Thunderbird release includes the fix?
The vulnerability was fixed in Thunderbird 155.