REDHAT-BUG-2366287: High severity thunderbird vulnerability

Published May 14, 2025
·
Updated

Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From header contains an (invalid) value "Spoofed Name ", Thunderbird treats spoofed as the actual address. This vulnerability affects Thunderbird < 128.10.1 and Thunderbird < 138.0.1.

Affected Software

2 affected components
Mozilla Thunderbird<128.10.1
Mozilla Thunderbird<138.0.1

Event History

May 14, 2025
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2366287?

The REDHAT-BUG-2366287 vulnerability is classified as a security vulnerability that allows sender spoofing.

2

How does REDHAT-BUG-2366287 affect Thunderbird?

REDHAT-BUG-2366287 affects Thunderbird by permitting invalid From addresses to be treated as legitimate, enabling sender spoofing.

3

What versions of Thunderbird are affected by REDHAT-BUG-2366287?

Mozilla Thunderbird versions up to 128.10.1 and 138.0.1 are affected by REDHAT-BUG-2366287.

4

How can I mitigate the risks associated with REDHAT-BUG-2366287?

To mitigate the risks of REDHAT-BUG-2366287, users should update to the latest available version of Thunderbird.

5

What kind of attacks can exploit REDHAT-BUG-2366287?

REDHAT-BUG-2366287 can be exploited in phishing attacks where an attacker uses spoofed email addresses to deceive recipients.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203