cbcvebase.
CVE-2026-0818
published 2026-01-28

CVE-2026-0818: When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled…

PriorityP419medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.16%
5.5th percentile
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled with HTML and CSS, then the decrypted contents were rendered in a context in which the CSS styles from the outer messages were active. If the user had additionally allowed loading of the remote content referenced by the outer email message, and the email was crafted by the sender using a combination of CSS rules and fonts and animations, then it was possible to extract the secret contents of the email. This vulnerability was fixed in Thunderbird 147.0.1 and Thunderbird 140.7.1.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianthunderbird< thunderbird 1:140.7.1esr-1~deb12u1 (bookworm)thunderbird 1:140.7.1esr-1~deb12u1 (bookworm)
mozillafirefox
mozillathunderbird< 140.7.1140.7.1
mozillathunderbird< 147.0.1147.0.1
mozillathunderbird>= 0 < 1:140.7.1esr-1~deb11u11:140.7.1esr-1~deb11u1
mozillathunderbird>= 0 < 1:140.7.1esr-1~deb12u11:140.7.1esr-1~deb12u1
mozillathunderbird>= 0 < 1:140.7.1esr-1~deb13u11:140.7.1esr-1~deb13u1
mozillathunderbird>= 0 < 1:140.7.1esr-11:140.7.1esr-1

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.