Medium severity5.3NVD Advisory· Published Jul 1, 2026· Updated Jul 6, 2026
CVE-2026-57962
CVE-2026-57962
Description
A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplied data into the Thunderbird LDAP client until it crashes due to memory exhaustion. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.
Affected products
4cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*+ 2 more
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*range: <152.0.1
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*range: <140.12.1
- (no CPE)range: before 152.0.1 and 140.12.1
Patches
Vulnerability mechanics
References
3- www.mozilla.org/security/advisories/mfsa2026-63/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2026-64/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdPermissions Required
News mentions
0No linked articles in our index yet.