CVE-2026-0818Improper Encoding or Escaping of Output in Mozilla Thunderbird

Severity
4.3MEDIUMNVD
EPSS
0.0%
top 99.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 28
Latest updateFeb 2

Description

When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled with HTML and CSS, then the decrypted contents were rendered in a context in which the CSS styles from the outer messages were active. If the user had additionally allowed loading of the remote content referenced by the outer email message, and the email was crafted by the sender using a combination of CSS rules and fonts and animations,

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDmozilla/thunderbird< 140.7.1+1
Debianmozilla/thunderbird< 1:140.7.1esr-1~deb11u1+3

🔴Vulnerability Details

3
OSV
CVE-2026-0818: When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted a2026-01-28
CVEList
CSS-based exfiltration of the content from partially encrypted emails when allowing remote content2026-01-28
GHSA
GHSA-r27j-r277-j56h: CSS-based exfiltration of the content from partially encrypted emails when allowing remote content2026-01-28

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2026-02-02
Red Hat
thunderbird: CSS-based exfiltration of the content from partially encrypted emails when allowing remote content2026-01-28
Debian
CVE-2026-0818: thunderbird - When a user explicitly requested Thunderbird to decrypt an inline OpenPGP messag...2026
Mozilla
Mozilla Foundation Security Advisory 2026-07: CVE-2026-0818
Mozilla
Mozilla Foundation Security Advisory 2026-08: CVE-2026-0818

🕵️Threat Intelligence

1
Wiz
CVE-2026-0818 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-0818 — Improper Encoding or Escaping of Output | cvebase