CVE-2025-0510: Mozilla Thunderbird
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.
Affected products
- Mozilla Thunderbird: from 128.0.1, before 128.7.0 (fixed in 128.7.0); from 131.0, before 135.0 (fixed in 135.0)
Published 2025-02-04. Last modified 2026-06-17.