CVE-2026-14899
published 2026-07-22CVE-2026-14899: The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.26%
17.6th percentile
The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | thunderbird | < Thunderbird 153 | Thunderbird 153 |
| mozilla | thunderbird | < Thunderbird 140.13 | Thunderbird 140.13 |
| mozilla | thunderbird | — | — |
| rhel10 | thunderbird-flatpak | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
thunderbird: Off-by-one out of bounds read in MIME header parser for forwarding
vendor_redhat·2026-07-22·CVSS 7.5
CVE-2026-14899 [HIGH] CWE-125 thunderbird: Off-by-one out of bounds read in MIME header parser for forwarding
thunderbird: Off-by-one out of bounds read in MIME header parser for forwarding
A flaw was found in Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:
The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: rhel10/thunderbird-flatpak (Red Hat Enterprise Linux 10) - Affected
Package: thunderbird (Red Hat Enterprise Linux 10) - Affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Out of support scope
Pac
Mozilla
Mozilla Foundation Security Advisory 2026-71: CVE-2026-14899
vendor_mozilla
CVE-2026-14899 Mozilla Foundation Security Advisory 2026-71: CVE-2026-14899
Mozilla Foundation Security Advisory 2026-71
CVE: CVE-2026-14899
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 153
Mozilla
Mozilla Foundation Security Advisory 2026-72: CVE-2026-14899
vendor_mozilla
CVE-2026-14899 Mozilla Foundation Security Advisory 2026-72: CVE-2026-14899
Mozilla Foundation Security Advisory 2026-72
CVE: CVE-2026-14899
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.13
VulDB
Mozilla Thunderbird up to 140.12/152 MIME Header Parsing off-by-one
vuldb·2026-07-22
CVE-2026-14899 [CRITICAL] Mozilla Thunderbird up to 140.12/152 MIME Header Parsing off-by-one
A vulnerability identified as critical has been detected in Mozilla Thunderbird up to 140.12/152. Affected is an unknown function of the component MIME Header Parsing. This manipulation causes off-by-one.
This vulnerability is tracked as CVE-2026-14899. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
GHSA
The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after t
ghsa_unreviewed·2026-07-22
CVE-2026-14899 The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after t
The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13.
No detection rules found.
No public exploits indexed.
2026-07-22
Published