Cryptographic issues in Mozilla Thunderbird - CVE-2025-26695
Published: July 22, 2025
Vulnerability identifier: #VU113123
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2025-26695
CWE-ID: CWE-310
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to usage of incorrect padding when downloading OpenPGP key from a WKD server. A remote attacker on the local network can learn the length of the requested email address.
Affected software
Mozilla Thunderbird
Gentoo Linux
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other
MozillaThunderbird-debuginfo
MozillaThunderbird
mail-client/thunderbird
mail-client/thunderbird-bin
thunderbird
thunderbird-debuginfo
thunderbird-debugsource
thunderbird-librnp-rnp
thunderbird-wayland
thunderbird (Ubuntu package)
Gentoo Linux
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other
MozillaThunderbird-debuginfo
MozillaThunderbird
mail-client/thunderbird
mail-client/thunderbird-bin
thunderbird
thunderbird-debuginfo
thunderbird-debugsource
thunderbird-librnp-rnp
thunderbird-wayland
thunderbird (Ubuntu package)
How to mitigate CVE-2025-26695
Install updates from vendor's website.
Mozilla Thunderbird - addressed in versions 136.0, 128.8.0
MozillaThunderbird-debugsource - update to 128.8.0-150200.8.203.1
MozillaThunderbird-translations-common - update to 128.8.0-150200.8.203.1
MozillaThunderbird-translations-other - update to 128.8.0-150200.8.203.1
MozillaThunderbird-debuginfo - update to 128.8.0-150200.8.203.1
MozillaThunderbird - update to 128.8.0-150200.8.203.1
mail-client/thunderbird - update to 128.9.0
mail-client/thunderbird-bin - update to 128.9.0
thunderbird - update to 128.11.1-1
thunderbird-debuginfo - update to 128.11.1-1
thunderbird-debugsource - update to 128.11.1-1
thunderbird-librnp-rnp - update to 128.11.1-1
thunderbird-wayland - update to 128.11.1-1
thunderbird (Ubuntu package) - update to 1:128.12.0+build1-0ubuntu0.22.04.1
MozillaThunderbird-debugsource - update to 128.8.0-150200.8.203.1
MozillaThunderbird-translations-common - update to 128.8.0-150200.8.203.1
MozillaThunderbird-translations-other - update to 128.8.0-150200.8.203.1
MozillaThunderbird-debuginfo - update to 128.8.0-150200.8.203.1
MozillaThunderbird - update to 128.8.0-150200.8.203.1
mail-client/thunderbird - update to 128.9.0
mail-client/thunderbird-bin - update to 128.9.0
thunderbird - update to 128.11.1-1
thunderbird-debuginfo - update to 128.11.1-1
thunderbird-debugsource - update to 128.11.1-1
thunderbird-librnp-rnp - update to 128.11.1-1
thunderbird-wayland - update to 128.11.1-1
thunderbird (Ubuntu package) - update to 1:128.12.0+build1-0ubuntu0.22.04.1