SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-84642

HIGH · CVSS 7.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-07

CyberRota Analysis

AI-Generated

The vulnerability arises from the improper handling of the `mail.allowed_attachment_hostnames` configuration setting in certain versions of Thunderbird, where unescaped values in a regular expression could allow unintended hostnames to match and serve remote attachments. This flaw poses a risk of unauthorized access to potentially malicious attachments, impacting users who rely on secure email practices. Organizations using affected versions of Thunderbird should prioritize updating to versions 155 or 153.2 to mitigate this risk.

CVE
CVE-2026-84642
Severity
HIGH
CVSS
7.5
EPSS
0.25%

Original NVD Description

The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also match and serve remote attachments. This vulnerability was fixed in Thunderbird 155 and Thunderbird 153.2.

Related CVEs

Other vulnerabilities affecting the same vendor(s)