SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14899

HIGH · CVSS 7.5 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

A vulnerability exists in the MIME header parsing code of Thunderbird, where an off-by-one error can lead to reading a byte beyond the allocated buffer, potentially causing application crashes. This issue affects users who have enabled the setting to view all headers when forwarding messages. Organizations using affected versions of Thunderbird should prioritize updating to version 153 or 140.13 to mitigate the risk of disruption.

CVE
CVE-2026-14899
Severity
HIGH
CVSS
7.5
EPSS
0.27%

Original NVD Description

The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13.

Related CVEs

Other vulnerabilities affecting the same vendor(s)