| Name | CVE-2026-57963 |
| Description | An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| thunderbird (PTS) | bullseye | 1:115.12.0-1~deb11u1 | vulnerable |
| bullseye (security) | 1:140.12.0esr-1~deb11u1 | vulnerable |
| bookworm, bookworm (security) | 1:140.12.0esr-1~deb12u1 | vulnerable |
| trixie (security), trixie | 1:140.12.0esr-1~deb13u1 | vulnerable |
| forky, sid | 1:140.12.0esr-1 | vulnerable |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| thunderbird | source | (unstable) | (unfixed) | | | |
Notes
[trixie] - thunderbird <postponed> (Minor issue, wait for next security round)
https://www.mozilla.org/en-US/security/advisories/mfsa2026-64/#CVE-2026-57963