CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. See the original NVD description below for full technical details.
CVE
CVE-2025-26695
Severity
MEDIUM
CVSS
5.3
EPSS
0.15%
Original NVD Description
When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested email address. This vulnerability was fixed in Thunderbird 136 and Thunderbird 128.8.
Related CVEs
Other vulnerabilities affecting the same vendor(s)