CVE-2026-0818
published 2026-01-28CVE-2026-0818: When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled…
PriorityP419medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.16%
5.5th percentile
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled with HTML and CSS, then the decrypted contents were rendered in a context in which the CSS styles from the outer messages were active. If the user had additionally allowed loading of the remote content referenced by the outer email message, and the email was crafted by the sender using a combination of CSS rules and fonts and animations, then it was possible to extract the secret contents of the email. This vulnerability was fixed in Thunderbird 147.0.1 and Thunderbird 140.7.1.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:140.7.1esr-1~deb12u1 (bookworm) | thunderbird 1:140.7.1esr-1~deb12u1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 140.7.1 | 140.7.1 |
| mozilla | thunderbird | < 147.0.1 | 147.0.1 |
| mozilla | thunderbird | >= 0 < 1:140.7.1esr-1~deb11u1 | 1:140.7.1esr-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:140.7.1esr-1~deb12u1 | 1:140.7.1esr-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:140.7.1esr-1~deb13u1 | 1:140.7.1esr-1~deb13u1 |
| mozilla | thunderbird | >= 0 < 1:140.7.1esr-1 | 1:140.7.1esr-1 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2026-02-02
CVE-2025-8031 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
thunderbird: CSS-based exfiltration of the content from partially encrypted emails when allowing remote content
vendor_redhat·2026-01-28·CVSS 4.3
CVE-2026-0818 [MEDIUM] thunderbird: CSS-based exfiltration of the content from partially encrypted emails when allowing remote content
thunderbird: CSS-based exfiltration of the content from partially encrypted emails when allowing remote content
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled with HTML and CSS, then the decrypted contents were rendered in a context in which the CSS styles from the outer messages were active. If the user had additionally allowed loading of the remote content referenced by the outer email message, and the email was crafted by the sender using a combination of CSS rules and fonts and animations, then it was possible to extract the secret contents of the email. This vulnerability affects Thunderbird < 147.0.1 and Thunderbird < 140.7.1.
A flaw was found in Thunderbird. The Mozilla
Debian
CVE-2026-0818: thunderbird - When a user explicitly requested Thunderbird to decrypt an inline OpenPGP messag...
vendor_debian·2026·CVSS 4.3
CVE-2026-0818 [MEDIUM] CVE-2026-0818: thunderbird - When a user explicitly requested Thunderbird to decrypt an inline OpenPGP messag...
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled with HTML and CSS, then the decrypted contents were rendered in a context in which the CSS styles from the outer messages were active. If the user had additionally allowed loading of the remote content referenced by the outer email message, and the email was crafted by the sender using a combination of CSS rules and fonts and animations, then it was possible to extract the secret contents of the email. This vulnerability affects Thunderbird < 147.0.1 and Thunderbird < 140.7.1.
Scope: local
bookworm: resolved (fixed in 1:140.7.1esr-1~deb12u1)
bullseye: resolved (fixed in 1:140.7.1esr-1~deb11u1)
forky: resolved (fixed in 1:140.7.1esr-
Mozilla
Mozilla Foundation Security Advisory 2026-07: CVE-2026-0818
vendor_mozilla·CVSS 4.3
CVE-2026-0818 [MEDIUM] Mozilla Foundation Security Advisory 2026-07: CVE-2026-0818
Mozilla Foundation Security Advisory 2026-07
CVE: CVE-2026-0818
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 147.0.1
Mozilla
Mozilla Foundation Security Advisory 2026-08: CVE-2026-0818
vendor_mozilla·CVSS 4.3
CVE-2026-0818 [MEDIUM] Mozilla Foundation Security Advisory 2026-08: CVE-2026-0818
Mozilla Foundation Security Advisory 2026-08
CVE: CVE-2026-0818
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 140.7.1
OSV
CVE-2026-0818: When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted a
osv·2026-01-28·CVSS 4.3
CVE-2026-0818 [MEDIUM] CVE-2026-0818: When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted a
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled with HTML and CSS, then the decrypted contents were rendered in a context in which the CSS styles from the outer messages were active. If the user had additionally allowed loading of the remote content referenced by the outer email message, and the email was crafted by the sender using a combination of CSS rules and fonts and animations, then it was possible to extract the secret contents of the email. This vulnerability affects Thunderbird < 147.0.1 and Thunderbird < 140.7.1.
GHSA
GHSA-r27j-r277-j56h: CSS-based exfiltration of the content from partially encrypted emails when allowing remote content
ghsa_unreviewed·2026-01-28
CVE-2026-0818 [MEDIUM] CWE-116 GHSA-r27j-r277-j56h: CSS-based exfiltration of the content from partially encrypted emails when allowing remote content
CSS-based exfiltration of the content from partially encrypted emails when allowing remote content. This vulnerability affects Thunderbird < 147.0.1 and Thunderbird < 140.7.1.
No detection rules found.
No public exploits indexed.
2026-01-28
Published