{"apiVersion":"1.0","identifier":"CVE-2026-4371","description":"A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.","publishedAt":"2026-03-24T21:16:29","lastModifiedAt":null,"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-4371","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","epssProbability":0.0036,"riskScore":0.76,"affectedProduct":"Thunderbird","affectedVersions":"<149,<140.9","vulnerabilityType":"Installed app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-4371","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-4371","en":"https://www.redsauce.net/en/cves/CVE-2026-4371","fr":"https://www.redsauce.net/fr/cves/CVE-2026-4371","pt":"https://www.redsauce.net/pt/cves/CVE-2026-4371","de":"https://www.redsauce.net/de/cves/CVE-2026-4371","sk":"https://www.redsauce.net/sk/cves/CVE-2026-4371","el":"https://www.redsauce.net/el/cves/CVE-2026-4371"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-4371"}}