Uncontrolled Memory Allocation in Mozilla Thunderbird - CVE-2026-57962
Published: July 22, 2026
Mozilla Thunderbird
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled memory allocation in the Thunderbird LDAP client when querying a malicious LDAP address-book server for autocomplete. A remote attacker can return arbitrarily large amounts of attacker-supplied data to cause a denial of service.