Mozilla · Thunderbird · CVE-2026-4371
**Name of the Vulnerable Software and Affected Versions**
Thunderbird versions prior to 149
Thunderbird versions prior to 140.9
**Description**
A specially crafted email could contain malformed strings with negative lengths, leading to a memory read outside of the intended buffer. Successful exploitation of this issue, potentially through a compromised mail server or connection, could cause Thunderbird to crash or leak sensitive data.
**Recommendations**
Update Thunderbird to version 149 or later.
Update Thunderbird to version 140.9 or later.