Multiple Interpretations of UI Input in Mozilla Thunderbird - CVE-2025-26696

 

Multiple Interpretations of UI Input in Mozilla Thunderbird - CVE-2025-26696

Published: July 22, 2025


Vulnerability identifier: #VU113122
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N]
CVE-ID: CVE-2025-26696
CWE-ID: CWE-450
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to improper validation of MIME email messages that claimed to contain an encrypted OpenPGP message. A remote attacker can force the application to incorrectly show the email message as being encrypted. 


Affected software

Mozilla Thunderbird
Gentoo Linux
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Package Hub 15
openSUSE Leap
Ubuntu
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other
MozillaThunderbird-debuginfo
MozillaThunderbird
mail-client/thunderbird
mail-client/thunderbird-bin
thunderbird (Ubuntu package)

How to mitigate CVE-2025-26696

Install updates from vendor's website.

Mozilla Thunderbird - addressed in versions 136.0, 128.8.0
MozillaThunderbird-debugsource - update to 128.8.0-150200.8.203.1
MozillaThunderbird-translations-common - update to 128.8.0-150200.8.203.1
MozillaThunderbird-translations-other - update to 128.8.0-150200.8.203.1
MozillaThunderbird-debuginfo - update to 128.8.0-150200.8.203.1
MozillaThunderbird - update to 128.8.0-150200.8.203.1
mail-client/thunderbird - update to 128.9.0
mail-client/thunderbird-bin - update to 128.9.0
thunderbird (Ubuntu package) - update to 1:128.12.0+build1-0ubuntu0.22.04.1

External References

Related Security Bulletins