CVE-2026-14899

HIGH

Off-by-one out of bounds read in MIME header parser for forwarding

Title source: cna
STIX 2.1

Description

The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13.

Scores

CVSS v3 7.5
EPSS 0.0026
EPSS Percentile 17.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-193
Status published
Products (2)
Mozilla/Thunderbird 140.13 - 140.*
Mozilla/Thunderbird 153
Published Jul 22, 2026
Tracked Since Jul 23, 2026