CVE-2025-26695

MEDIUM

Thunderbird < 136 - Info Disclosure

Title source: llm
STIX 2.1

Description

When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested email address. This vulnerability was fixed in Thunderbird 136 and Thunderbird 128.8.

Scores

CVSS v3 5.3
EPSS 0.0005
EPSS Percentile 15.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (3)
mozilla/thunderbird < 128.8.0
Mozilla/Thunderbird 128.8 - 128.*
Mozilla/Thunderbird 136
Published Mar 10, 2025
Tracked Since Feb 18, 2026