CVE-2026-103500: Mozilla Thunderbird
EPSS: 0.2% chance of exploitation in the next 30 days.
An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4.
Affected products
- Mozilla Thunderbird
Published 2026-09-30. Last modified 2026-09-30.