CVE-2026-103500
An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4.
- Published Sep 30, 2026
- Not yet scored
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available