PT-2025-10625 · Mozilla+6 · Thunderbird+6

Daniel Huigens

·

Published

2025-02-13

·

Updated

2025-10-08

·

CVE-2025-26695

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 136 Thunderbird versions prior to 128.8
Description The issue arises when requesting an OpenPGP key from a WKD server, where an incorrect padding size was used. This could allow a network observer to learn the length of the requested email address.
Recommendations For versions prior to 136, update to version 136 or later. For versions prior to 128.8, update to version 128.8 or later.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2025-7695
BDU:2025-02578
CVE-2025-26695
DLA-4081-1
DSA-5876-1
OESA-2025-1835
OPENSUSE-SU-2025_0849-1
SUSE-SU-2025:0849-1
USN-7663-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Red Os
Suse
Thunderbird
Ubuntu