Information disclosure in Mozilla Thunderbird - CVE-2026-0818
Published: January 29, 2026
Vulnerability identifier: #VU122117
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0818
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the way CSS is handled within the application. A remote attacker can exfiltrate content from partially encrypted emails when allowing remote content.
Affected software
Mozilla Thunderbird
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
thunderbird (Ubuntu package)
thunderbird (Debian package)
MozillaThunderbird-debugsource
MozillaThunderbird
MozillaThunderbird-debuginfo
MozillaThunderbird-translations-other
MozillaThunderbird-translations-common
thunderbird-debuginfo
thunderbird-wayland
thunderbird-librnp-rnp
thunderbird-debugsource
thunderbird
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
thunderbird (Ubuntu package)
thunderbird (Debian package)
MozillaThunderbird-debugsource
MozillaThunderbird
MozillaThunderbird-debuginfo
MozillaThunderbird-translations-other
MozillaThunderbird-translations-common
thunderbird-debuginfo
thunderbird-wayland
thunderbird-librnp-rnp
thunderbird-debugsource
thunderbird
How to mitigate CVE-2026-0818
Install updates from vendor's website.
Mozilla Thunderbird - addressed in versions 140.7.1, 147.0.1
thunderbird (Ubuntu package) - update to 1:140.7.1+build1-0ubuntu0.22.04.1
thunderbird (Debian package) - addressed in versions 1:140.7.1esr-1~deb12u1, 1:140.7.1esr-1~deb13u1
MozillaThunderbird-debugsource - update to 140.7.1-150200.8.254.1
MozillaThunderbird - update to 140.7.1-150200.8.254.1
MozillaThunderbird-debuginfo - update to 140.7.1-150200.8.254.1
MozillaThunderbird-translations-other - update to 140.7.1-150200.8.254.1
MozillaThunderbird-translations-common - update to 140.7.1-150200.8.254.1
thunderbird-debuginfo - addressed in versions 140.7.2-1, 140.8.0-1
thunderbird-wayland - addressed in versions 140.7.2-1, 140.8.0-1
thunderbird-librnp-rnp - addressed in versions 140.7.2-1, 140.8.0-1
thunderbird-debugsource - addressed in versions 140.7.2-1, 140.8.0-1
thunderbird - addressed in versions 140.7.2-1, 140.8.0-1
thunderbird (Ubuntu package) - update to 1:140.7.1+build1-0ubuntu0.22.04.1
thunderbird (Debian package) - addressed in versions 1:140.7.1esr-1~deb12u1, 1:140.7.1esr-1~deb13u1
MozillaThunderbird-debugsource - update to 140.7.1-150200.8.254.1
MozillaThunderbird - update to 140.7.1-150200.8.254.1
MozillaThunderbird-debuginfo - update to 140.7.1-150200.8.254.1
MozillaThunderbird-translations-other - update to 140.7.1-150200.8.254.1
MozillaThunderbird-translations-common - update to 140.7.1-150200.8.254.1
thunderbird-debuginfo - addressed in versions 140.7.2-1, 140.8.0-1
thunderbird-wayland - addressed in versions 140.7.2-1, 140.8.0-1
thunderbird-librnp-rnp - addressed in versions 140.7.2-1, 140.8.0-1
thunderbird-debugsource - addressed in versions 140.7.2-1, 140.8.0-1
thunderbird - addressed in versions 140.7.2-1, 140.8.0-1