CVE-2026-84642

NameCVE-2026-84642
DescriptionThe values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also match and serve remote attachments. This vulnerability was fixed in Thunderbird 155 and Thunderbird 153.2.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
thunderbird (PTS)bookworm1:140.12.0esr-1~deb12u1fixed
bookworm (security)1:140.14.0esr-1~deb12u1fixed
trixie1:140.12.0esr-1~deb13u1fixed
trixie (security)1:140.14.0esr-1~deb13u1fixed
forky, sid1:140.14.0esr-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
thunderbirdsource(unstable)(not affected)

Notes

- thunderbird <not-affected> (Thunderbird ESR140 series not affected)
https://www.mozilla.org/en-US/security/advisories/mfsa2026-86/#CVE-2026-84642

Search for package or bug name: Reporting problems