CVE-2026-4371
Severity
7.4HIGH
EPSS
0.1%
top 82.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 24
Description
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 2.2 | Impact: 5.2
Affected Packages3 packages
🔴Vulnerability Details
3GHSA▶
GHSA-4p49-pghr-968w: A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer↗2026-03-24
OSV▶
CVE-2026-4371: A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer↗2026-03-24
📋Vendor Advisories
4Debian▶
CVE-2026-4371: thunderbird - A malicious mail server could send malformed strings with negative lengths, caus...↗2026