SB2026080812 - Debian update for thunderbird
Published: August 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 35 vulnerabilities.
1) Protection mechanism failure (CVE-ID: CVE-2026-16383)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security restriction.
The vulnerability exists due to a mitigation bypass in the DOM: Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass a security restriction.
2) Out-of-bounds read (CVE-ID: CVE-2026-16368)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to incorrect boundary conditions in the JavaScript: WebAssembly component when compiling or executing WebAssembly content. A remote attacker can supply crafted WebAssembly content to cause a denial of service.
3) Integer overflow (CVE-ID: CVE-2026-16369)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer overflow in the JavaScript: WebAssembly component when compiling or executing WebAssembly content. A remote attacker can supply crafted WebAssembly content to execute arbitrary code.
4) Improper privilege management (CVE-ID: CVE-2026-16371)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation operations. A remote attacker can trigger crafted navigation behavior to escalate privileges.
5) Information disclosure (CVE-ID: CVE-2026-16374)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an information disclosure flaw in the Framework component in DevTools when using developer tools functionality. A remote attacker can trigger the flaw through crafted developer tools interactions to disclose sensitive information.
6) Protection mechanism failure (CVE-ID: CVE-2026-16375)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the Networking: HTTP component when handling HTTP traffic. A remote attacker can trigger crafted HTTP behavior to bypass site isolation.
7) Protection mechanism failure (CVE-ID: CVE-2026-16377)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security restriction.
The vulnerability exists due to a mitigation bypass in the PDF Viewer component when rendering PDF content. A remote attacker can supply crafted PDF content to bypass a security restriction.
8) Improper privilege management (CVE-ID: CVE-2026-16379)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Content Processes component when handling content processes. A remote attacker can trigger crafted content process behavior to escalate privileges.
9) Improper access control (CVE-ID: CVE-2026-16381)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the Networking: DNS component when resolving DNS requests. A remote attacker can trigger crafted DNS behavior to bypass the same-origin policy.
10) Incorrect calculation (CVE-ID: CVE-2026-16363)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to JIT miscompilation in the JavaScript: WebAssembly component when compiling and executing WebAssembly content. A remote attacker can supply crafted WebAssembly content to execute arbitrary code.
11) Protection mechanism failure (CVE-ID: CVE-2026-16387)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass site isolation.
12) Protection mechanism failure (CVE-ID: CVE-2026-16390)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security restriction.
The vulnerability exists due to a mitigation bypass in the Enterprise Policies component when applying enterprise policies. A remote attacker can trigger crafted policy conditions to bypass a security restriction.
13) Information disclosure (CVE-ID: CVE-2026-16391)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an information disclosure flaw in the Storage: IndexedDB component when handling stored web data. A remote attacker can trigger crafted storage interactions to disclose sensitive information.
14) Improper privilege management (CVE-ID: CVE-2026-16396)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in WebExtensions when using extension functionality. A remote user can abuse extension functionality to escalate privileges.
Exploitation requires the use of WebExtensions.
15) Information disclosure (CVE-ID: CVE-2026-16405)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an information disclosure flaw in the Networking: WebSockets component when handling WebSocket connections. A remote attacker can trigger crafted WebSocket behavior to disclose sensitive information.
16) Buffer overflow (CVE-ID: CVE-2026-16412)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple components when processing crafted content. A remote attacker can trigger memory corruption using crafted content to execute arbitrary code.
Mozilla reported that some of the underlying bugs showed evidence of memory corruption.
17) Uncontrolled Memory Allocation (CVE-ID: CVE-2026-57962)
CWE-ID: CWE-789 - Uncontrolled Memory Allocation
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled memory allocation in the Thunderbird LDAP client when querying a malicious LDAP address-book server for autocomplete. A remote attacker can return arbitrarily large amounts of attacker-supplied data to cause a denial of service.
18) Cross-site scripting (CVE-ID: CVE-2026-57963)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to manipulate the chat user interface.
The vulnerability exists due to improper neutralization of HTML content in the chat message rendering component when processing HTML chat messages sent via Matrix or XMPP. A remote attacker can send a crafted HTML chat message containing styled content, phishing links, and CSS to manipulate the chat user interface.
19) Incorrect calculation (CVE-ID: CVE-2026-16355)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when executing script content. A remote attacker can convince the victim to visit a specially crafted website or URL to execute arbitrary code.
20) Access of Uninitialized Pointer (CVE-ID: CVE-2026-15718)
CWE-ID: CWE-824 - Access of Uninitialized Pointer
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an invalid pointer in the JavaScript: WebAssembly component when processing web content. A remote attacker can trigger the vulnerable component to execute arbitrary code.
21) Improper access control (CVE-ID: CVE-2026-15719)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to manipulate DOM elements.
The vulnerability exists due to improper access restrictions within the Navigation component. A remote attacker can trick the victim into visiting a specially crafted website and manipulate arbitrary DOM object, bypassing site isolation in DOM.
22) Improper access control (CVE-ID: CVE-2026-16349)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation. A remote attacker can convince the victim to visit a specially crafted website or URL to bypass the same-origin policy.
23) Input validation error (CVE-ID: CVE-2026-16350)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to incorrect boundary conditions in the Audio/Video: cubeb component when processing media content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.
24) Use-after-free (CVE-ID: CVE-2026-16351)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the DOM: Navigation component when handling navigation. A remote attacker can convince the victim to visit a specially crafted website or URL to escape the sandbox.
25) Use-after-free (CVE-ID: CVE-2026-16352)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the Disability Access APIs component when interacting with accessibility functionality. A remote attacker can convince the victim to visit a specially crafted website or URL to escape the sandbox.
26) NULL pointer dereference (CVE-ID: CVE-2026-16353)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to an invalid pointer in the DOM: Bindings (WebIDL) component when processing web content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.
27) Information disclosure (CVE-ID: CVE-2026-16354)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the Graphics: ImageLib component when processing image content. A remote attacker can convince the victim to visit a specially crafted website or URL to disclose sensitive information.
28) Off-by-one (CVE-ID: CVE-2026-14899)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to an off-by-one error within the MIME header parser. A remote attacker can trick the victim into opening a specially crafted email and read contents of memory on the system or crash the application.
29) Use-after-free (CVE-ID: CVE-2026-16356)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the Disability Access APIs component when interacting with accessibility functionality. A remote attacker can convince the victim to visit a specially crafted website or URL to escape the sandbox.
30) Input validation error (CVE-ID: CVE-2026-16357)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to incorrect boundary conditions in the Graphics component when processing rendered content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.
31) Improper access control (CVE-ID: CVE-2026-16358)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the Graphics: WebRender component when rendering content. A remote attacker can convince the victim to visit a specially crafted website or URL to bypass site isolation.
32) Input validation error (CVE-ID: CVE-2026-16359)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to incorrect boundary conditions in the Audio/Video: GMP component when processing media content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.
33) Buffer overflow (CVE-ID: CVE-2026-16360)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple components when processing web content. A remote attacker can convince the victim to visit a specially crafted website or URL to execute arbitrary code.
Some of the underlying bugs showed evidence of memory corruption.
34) Buffer overflow (CVE-ID: CVE-2026-16361)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple components when processing web content. A remote attacker can convince the victim to visit a specially crafted website or URL to execute arbitrary code.
Some of the underlying bugs showed evidence of memory corruption.
35) Use-after-free (CVE-ID: CVE-2026-16362)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the WebRTC: Audio/Video component when processing real-time audio or video content. A remote attacker can trigger the flaw using crafted real-time media interactions to execute arbitrary code.
Remediation
Install update from vendor's website.