CVE-2026-4371
published 2026-03-24CVE-2026-4371: A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or…
PriorityP344high7.4CVSS 3.1
AVNACHPRNUINSUCHINAH
EPSS
0.36%
28.6th percentile
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:140.9.0esr-1~deb12u1 (bookworm) | thunderbird 1:140.9.0esr-1~deb12u1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 140.9.0 | 140.9.0 |
| mozilla | thunderbird | < 149.0 | 149.0 |
| mozilla | thunderbird | >= 0 < 1:140.9.0esr-1~deb11u1 | 1:140.9.0esr-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:140.9.0esr-1~deb12u1 | 1:140.9.0esr-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:140.9.0esr-1~deb13u1 | 1:140.9.0esr-1~deb13u1 |
| mozilla | thunderbird | >= 0 < 1:140.9.0esr-1 | 1:140.9.0esr-1 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
osv7.4HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Thunderbird up to 140.8/148 Email out-of-bounds (Nessus ID 303506 / WID-SEC-2026-0850)
vuldb·2026-07-01·CVSS 7.4
CVE-2026-4371 [HIGH] Mozilla Thunderbird up to 140.8/148 Email out-of-bounds (Nessus ID 303506 / WID-SEC-2026-0850)
A vulnerability was found in Mozilla Thunderbird up to 140.8/148. It has been classified as problematic. This impacts an unknown function of the component Email Handler. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2026-4371. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-4p49-pghr-968w: A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer
ghsa_unreviewed·2026-03-24
CVE-2026-4371 [HIGH] CWE-126 GHSA-4p49-pghr-968w: A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.
OSV
CVE-2026-4371: A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer
osv·2026-03-24·CVSS 7.4
CVE-2026-4371 [HIGH] CVE-2026-4371: A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.
Red Hat
thunderbird: Out of bounds read in IMAP parsing
vendor_redhat·2026-03-24·CVSS 7.4
CVE-2026-4371 [HIGH] CWE-130 thunderbird: Out of bounds read in IMAP parsing
thunderbird: Out of bounds read in IMAP parsing
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.
A flaw was found in Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashin
Debian
CVE-2026-4371: thunderbird - A malicious mail server could send malformed strings with negative lengths, caus...
vendor_debian·2026·CVSS 7.4
CVE-2026-4371 [HIGH] CVE-2026-4371: thunderbird - A malicious mail server could send malformed strings with negative lengths, caus...
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.
Scope: local
bookworm: resolved (fixed in 1:140.9.0esr-1~deb12u1)
bullseye: resolved (fixed in 1:140.9.0esr-1~deb11u1)
forky: resolved (fixed in 1:140.9.0esr-1)
sid: resolved (fixed in 1:140.9.0esr-1)
trixie: resolved (fixed in 1:140.9.0esr-1~deb13u1)
Mozilla
Mozilla Foundation Security Advisory 2026-23: CVE-2026-4371
vendor_mozilla·CVSS 7.4
CVE-2026-4371 [HIGH] Mozilla Foundation Security Advisory 2026-23: CVE-2026-4371
Mozilla Foundation Security Advisory 2026-23
CVE: CVE-2026-4371
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 149
Mozilla
Mozilla Foundation Security Advisory 2026-24: CVE-2026-4371
vendor_mozilla·CVSS 7.4
CVE-2026-4371 [HIGH] Mozilla Foundation Security Advisory 2026-24: CVE-2026-4371
Mozilla Foundation Security Advisory 2026-24
CVE: CVE-2026-4371
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.9
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-32776 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2026-32776 [MEDIUM] CVE-2026-32776 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32776 :
Alma Linux vulnerability analysis and mitigation
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
Source : NVD
## 5.5
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
Alma Linux
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libexpat-devel
firefox-debugsource
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 20, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 17, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Mar 17, 2026
Echo Severity
Wiz
CVE-2026-4371 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-4371 [HIGH] CVE-2026-4371 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4371 :
NixOS vulnerability analysis and mitigation
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.
Source : NVD
## 7.4
Score
Published March 24, 2026
Severity HIGH
CNA Score 7.4
Affected Technologies
NixOS
Mozilla Thunderbird
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Mo
Wiz
CVE-2026-25210 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2026-25210 [MEDIUM] CVE-2026-25210 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25210 :
Alma Linux vulnerability analysis and mitigation
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
Source : NVD
## 7.8
Score
Published January 30, 2026
Severity HIGH
CNA Score 6.9
Affected Technologies
Alma Linux
CBL Mariner
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libxmltok
libexpat1
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23 Severity HIGH Has Fix Added at: Feb 04, 2026
Alpine edge Severity HIGH Has Fix Added at: Feb 03, 2026
CBL-Mariner 2.0 Severity MEDIUM
Wiz
ELSA-2026-1240 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-1240 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-1240 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-1240: fence-agents security update (IMPORTANT)
Source : NVD
Published January 27, 2026
Severity HIGH
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
fence-agents-compute
fence-agents-eps
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-20
Wiz
ELSA-2026-0991 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-0991 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-0991 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-0991: glib2 security update (MODERATE)
Source : NVD
Published January 22, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
glib2
glib2-devel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4721
CRITICAL
9.8
Ni
Wiz
ELSA-2025-23141 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2025-23141 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2025-23141 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2025-23141: ruby security update (MODERATE)
Source : NVD
Published December 11, 2025
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
rubygem-minitest
rubygem-rbs
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4721
CRIT
Wiz
ELSA-2026-1592 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-1592 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-1592 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-1592: iperf3 security update (MODERATE)
Source : NVD
Published January 29, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
iperf3
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4721
CRITICAL
9.8
NixOS
Mozill
Wiz
ELSA-2026-0126 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-0126 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-0126 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-0126: poppler security update (MODERATE)
Source : NVD
Published January 6, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
poppler-cpp
poppler-devel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4721
CRITICAL
Wiz
ELSA-2025-23139 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2025-23139 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2025-23139 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2025-23139: libsoup3 security update (MODERATE)
Source : NVD
Published December 11, 2025
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libsoup3
libsoup3-devel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4721
CRITI
Wiz
ELSA-2026-1595 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-1595 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-1595 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-1595: iperf3 security update (MODERATE)
Source : NVD
Published January 29, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
iperf3
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4721
CRITICAL
9.8
NixOS
Mozill
Wiz
CVE-2026-21991 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21991 [MEDIUM] CVE-2026-21991 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21991 :
Linux Oracle vulnerability analysis and mitigation
A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.
Source : NVD
## 5.5
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
dtrace
dtrace-devel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV
Wiz
CVE-2026-24515 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.9
CVE-2026-24515 [LOW] CVE-2026-24515 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24515 :
Alma Linux vulnerability analysis and mitigation
In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.
Source : NVD
## 2.5
Score
Published January 23, 2026
Severity LOW
CNA Score 2.9
Affected Technologies
Alma Linux
CBL Mariner
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
mingw-expat
libexpat1-32bit
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23 Severity LOW Has Fix Added at: Feb 04, 2026
Alpine edge Severity LOW Has Fix Added at: Feb 03, 2026
CBL-Mariner 2.0 Severity LOW Has Fix Added at: Feb 08, 2026
CBL-Mariner 3.0 Severity LOW Has
Wiz
CVE-2026-32778 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.9
CVE-2026-32778 [LOW] CVE-2026-32778 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32778 :
Alma Linux vulnerability analysis and mitigation
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
Source : NVD
## 5.5
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 2.9
Affected Technologies
Alma Linux
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
thunderbird
libexpat-devel
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 19, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 17, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Mar
Wiz
ELSA-2026-1518 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-1518 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-1518 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-1518: grafana-pcp security update (IMPORTANT)
Source : NVD
Published January 28, 2026
Severity HIGH
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
grafana-pcp
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4721
CRITICAL
9.8
NixO
Wiz
CVE-2026-32777 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2026-32777 [MEDIUM] CVE-2026-32777 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32777 :
Alma Linux vulnerability analysis and mitigation
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
Source : NVD
## 5.5
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
Alma Linux
Linux Debian
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libexpat1
seal-expat
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 19, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 17, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Mar 17, 2026
Echo Severity MEDIUM Has Fix Added at: Mar 17, 2026
Red
Wiz
ELSA-2026-1380 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-1380 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-1380 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-1380: osbuild-composer security update (MODERATE)
Source : NVD
Published January 28, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
osbuild-composer-core
osbuild-composer-worker
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published
Wiz
ELSA-2026-1852 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-1852 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-1852 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-1852: util-linux security update (MODERATE)
Source : NVD
Published February 4, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libsmartcols-devel
util-linux-user
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4
Wiz
CVE-2026-4177 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-4177 [MEDIUM] CVE-2026-4177 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4177 :
Alma Linux vulnerability analysis and mitigation
YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter.
The heap overflow occurs when class names exceed the initial 512-byte allocation.
The base64 decoder could read past the buffer end on trailing newlines.
strtok mutated n->type_id in place, corrupting shared node data.
A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.
Source : NVD
## 9.1
Score
Published March 16, 2026
Severity CRITICAL
CNA Score 9.1
Affected Technologies
Alma Linux
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Dat
Bugzilla
CVE-2026-4371 thunderbird: Out of bounds read in IMAP parsing
bugzilla·2026-03-24·CVSS 7.4
CVE-2026-4371 [HIGH] CVE-2026-4371 thunderbird: Out of bounds read in IMAP parsing
CVE-2026-4371 thunderbird: Out of bounds read in IMAP parsing
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6188 https://access.redhat.com/errata/RHSA-2026:6188
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:6342 https://access.redhat.com/errata/RHSA-2026:6342
---
This issue has been address
https://bugzilla.mozilla.org/show_bug.cgi?id=2023493https://www.mozilla.org/security/advisories/mfsa2026-23/https://www.mozilla.org/security/advisories/mfsa2026-24/https://access.redhat.com/errata/RHSA-2026:6188https://access.redhat.com/errata/RHSA-2026:6342https://access.redhat.com/errata/RHSA-2026:6917https://access.redhat.com/errata/RHSA-2026:8284https://access.redhat.com/errata/RHSA-2026:8285https://access.redhat.com/errata/RHSA-2026:8286https://access.redhat.com/errata/RHSA-2026:8287https://access.redhat.com/errata/RHSA-2026:8288https://access.redhat.com/errata/RHSA-2026:8289https://access.redhat.com/errata/RHSA-2026:8290https://access.redhat.com/errata/RHSA-2026:8315https://access.redhat.com/errata/RHSA-2026:8850https://access.redhat.com/security/cve/CVE-2026-4371https://bugzilla.redhat.com/show_bug.cgi?id=2451001https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4371.json
2026-03-24
Published