CVE-2026-57962
EUVD-2026-4086101.07.2026, 02:17
A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplied data into the Thunderbird LDAP client until it crashes due to memory exhaustion. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mozilla | thunderbird_esr | 𝑥 < 140.12.1 |
| mozilla | thunderbird | 𝑥 < 152.0.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases