CVE-2026-84642: Allowed UNC hostnames for attachments interpreted as a regular expression

Published Sep 1, 2026
·
Updated

The values of the mail.allowedattachmenthostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also match and serve remote attachments.

Affected Software

3 affected componentsFixes available
Mozilla Thunderbird<155
Mozilla Thunderbird<155
155
Mozilla Thunderbird<153.2
153.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 155
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 153.2
  3. Upgrade

    Upgrade Thunderbird to a version that resolves this vulnerability.

    Fixed in 155
  4. Configuration

    Update the value of the advanced config setting mail.allowed_attachment_hostnames to be regex-safe by escaping any regex metacharacters, preventing unintended hostnames from matching attachment-serving rules.

    Thunderbird mail.allowed_attachment_hostnames = Use hostname patterns escaped for regular expressions (ensure regex metacharacters are escaped so only intended hostnames match).

Event History

Sep 1, 2026
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·09:33 PM
Data Sourced
via MITRE·09:33 PM
Description

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

Who is exposed to this issue?

Users of Thunderbird configurations that use the mail.allowed_attachment_hostnames advanced setting may be exposed. The issue applies when configured hostname values can be interpreted as regular-expression patterns that also match unintended UNC hosts.

2

What is required for exploitation?

An attacker would need to use an unintended hostname that matches the regular expression derived from an allowed hostname entry and cause remote attachments to be served from that host. The provided information does not establish that default Thunderbird configurations are affected.

3

How can administrators mitigate the issue before updating?

Review mail.allowed_attachment_hostnames entries for hostname characters that have special meaning in regular expressions, since those values were not escaped. Updating to Thunderbird 155 applies the stated fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203