cbcvebase.
CVE-2026-57962
published 2026-07-01

CVE-2026-57962: A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of…

PriorityP426medium5.3CVSS 3.1
AVNACHPRNUIRSUCNINAH
EPSS
0.22%
12.6th percentile
A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplied data into the Thunderbird LDAP client until it crashes due to memory exhaustion. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.

Affected

4 ranges
VendorProductVersion rangeFixed in
mozillathunderbird< Thunderbird 152.0.1Thunderbird 152.0.1
mozillathunderbird< Thunderbird 140.12.1Thunderbird 140.12.1
mozillathunderbird< 140.12.1140.12.1
mozillathunderbird< 152.0.1152.0.1

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.