CVE-2024-11159: Mozilla Thunderbird
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < 132.0.1.
Affected products
- Mozilla Thunderbird: before 128.4.3 (fixed in 128.4.3); from 129.0, before 132.0.1 (fixed in 132.0.1)
Published 2024-11-13. Last modified 2026-06-17.