CVE-2025-26695: Mozilla Thunderbird
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested email address. This vulnerability was fixed in Thunderbird 136 and Thunderbird 128.8.
Affected products
- Mozilla Thunderbird: before 128.8.0 (fixed in 128.8.0); from 129.0, before 136.0 (fixed in 136.0)
Published 2025-03-10. Last modified 2026-06-17.