CVE-2026-84642
NixOS 脆弱性の分析と軽減

概要

CVE-2026-84642 is an authorization bypass vulnerability in Mozilla Thunderbird caused by unescaped regular expression handling of the mail.allowed_attachment_hostnames advanced configuration setting. When hostnames configured in this allowlist contain regex metacharacters, they are used directly in a regular expression without proper escaping, allowing certain unintended hostnames to match and serve remote attachments. The vulnerability affects Thunderbird versions prior to 155.0 (in the 154.x branch) and prior to 153.2.0 (in the ESR branch), and was disclosed on September 1, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Mozilla MFSA2026-86, Mozilla MFSA2026-88).

技術的な詳細

The root cause is classified as CWE-1333 (Inefficient Regular Expression Complexity) and maps to CAPEC-492 (Regular Expression Exponential Blowup), reflecting improper handling of user-supplied input in regex construction. Thunderbird's attachment hostname allowlist feature reads values from mail.allowed_attachment_hostnames and incorporates them directly into a regular expression pattern without escaping special regex metacharacters. For hostnames that happen to contain characters with regex significance (e.g., ., *, +), the resulting pattern can inadvertently match additional, unintended hostnames, bypassing the intended access restriction. This is a network-accessible flaw requiring no authentication or user interaction, as the matching occurs automatically when remote attachments are processed (Mozilla MFSA2026-86, Mozilla MFSA2026-88).

影響

Successful exploitation allows an unauthenticated remote attacker to serve remote attachments from hostnames that should be blocked by the configured allowlist, effectively bypassing Thunderbird's attachment hostname restriction. The primary impact is a high confidentiality risk — users may unknowingly load or interact with remote content from unauthorized sources — while integrity and availability are not directly affected. The scope is limited to Thunderbird clients with a non-empty mail.allowed_attachment_hostnames configuration containing hostnames with regex-special characters (Mozilla MFSA2026-86, Mozilla MFSA2026-88).

エクスプロイト可能性

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The vulnerability is automatable (per NVD SSVC assessment) but has only partial technical impact. The EPSS score is approximately 0.148%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.

軽減策と回避策

Mozilla has released patches addressing this vulnerability in Thunderbird 155 and Thunderbird ESR 153.2, both announced on September 1, 2026. Users should update to one of these versions immediately via the built-in updater or their platform's package manager. As an additional precaution, administrators should review the mail.allowed_attachment_hostnames setting in Thunderbird's advanced configuration (about:config) to ensure it contains only intended, properly formatted hostnames, and consider clearing or restricting this setting if remote attachment functionality is not required (Mozilla MFSA2026-86, Mozilla MFSA2026-88).

コミュニティの反応

Mozilla rated the impact of CVE-2026-84642 as "low" within the broader Thunderbird 155 and 153.2 security advisories, which collectively addressed numerous higher-severity issues. The vulnerability was reported by researchers ChinhNguyen and Lowk3yz. No significant independent researcher commentary, media coverage, or notable community discussion specific to this CVE has been identified beyond standard vulnerability aggregator coverage (Mozilla MFSA2026-86, Mozilla MFSA2026-88).

関連情報

Linuxディストリビューションの修正状況

主要なLinuxディストリビューションおよびそのリリースにおける修正の提供状況。

Debian

修正済

bookworm

thunderbird

修正済

sid

thunderbird

修正済

trixie

thunderbird

修正済

Ubuntu

不明

devel

thunderbird

不明

jammy

thunderbird

不明

noble

thunderbird

不明

resolute

thunderbird

不明

Alpine

影響

edge

68.5.0-r0

影響

v3.24

151.0.1-r0

影響

ソースこのレポートは AI を使用して生成されました

関連 NixOS 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • headlamp-fips
いいえはいSep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • argo-workflows-3.7
いいえはいSep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
いいえはいSep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
いいえはいSep 01, 2026
CVE-2026-32773MEDIUM6.1
  • NixOS logoNixOS
  • spark
いいえはいSep 02, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者