CVE-2026-57962
published 2026-07-01CVE-2026-57962: A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of…
PriorityP426medium5.3CVSS 3.1
AVNACHPRNUIRSUCNINAH
EPSS
0.22%
12.6th percentile
A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplied data into the Thunderbird LDAP client until it crashes due to memory exhaustion. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | thunderbird | < Thunderbird 152.0.1 | Thunderbird 152.0.1 |
| mozilla | thunderbird | < Thunderbird 140.12.1 | Thunderbird 140.12.1 |
| mozilla | thunderbird | < 140.12.1 | 140.12.1 |
| mozilla | thunderbird | < 152.0.1 | 152.0.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
thunderbird: Thunderbird: Denial of Service via malicious LDAP server
vendor_redhat·2026-07-01·CVSS 5.3
CVE-2026-57962 [MEDIUM] CWE-1050 thunderbird: Thunderbird: Denial of Service via malicious LDAP server
thunderbird: Thunderbird: Denial of Service via malicious LDAP server
A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplied data into the Thunderbird LDAP client until it crashes due to memory exhaustion. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.
A flaw was found in Thunderbird. A remote attacker, by operating a malicious Lightweight Directory Access Protocol (LDAP) server, can cause a Thunderbird client to crash due to memory exhaustion. This occurs when a user's Thunderbird client is configured to query the malicious LDAP server for address-book autocomplete, allowing the server to send an excessive amount of data. This can lead to a Denial of S
Mozilla
Mozilla Foundation Security Advisory 2026-63: CVE-2026-57962
vendor_mozilla·CVSS 5.3
CVE-2026-57962 [MEDIUM] Mozilla Foundation Security Advisory 2026-63: CVE-2026-57962
Mozilla Foundation Security Advisory 2026-63
CVE: CVE-2026-57962
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 152.0.1
Mozilla
Mozilla Foundation Security Advisory 2026-64: CVE-2026-57962
vendor_mozilla·CVSS 5.3
CVE-2026-57962 [MEDIUM] Mozilla Foundation Security Advisory 2026-64: CVE-2026-57962
Mozilla Foundation Security Advisory 2026-64
CVE: CVE-2026-57962
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.12.1
GHSA
A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplied data into the Thunderbird LDAP client u
ghsa_unreviewed·2026-07-01
CVE-2026-57962 [MEDIUM] CWE-400 A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplied data into the Thunderbird LDAP client u
A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplied data into the Thunderbird LDAP client until it crashes due to memory exhaustion. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.
No detection rules found.
No public exploits indexed.
2026-07-01
Published