CVE-2019-11739: Mozilla Thunderbird
Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.
Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 68.1 and Thunderbird < 60.9.
Affected products
- Mozilla Thunderbird: before 60.9.0 (fixed in 60.9.0); from 68.0, before 68.1.0 (fixed in 68.1.0)
Published 2019-09-27. Last modified 2026-06-17.