Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-92240

A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 50.7%
CVSS Severity
CVSS v3 Score 9.1
Products affected by CVE-2026-92240


Contact Us

Shodan ® - All rights reserved