AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-26695

MEDIUM · CVSS 5.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-03-10 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.3. See the original NVD description below for full technical details.

CVE
CVE-2025-26695
Severity
MEDIUM
CVSS
5.3
EPSS
0.15%

Original NVD Description

When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested email address. This vulnerability was fixed in Thunderbird 136 and Thunderbird 128.8.

Related CVEs

Other vulnerabilities affecting the same vendor(s)