CVE-2026-84642
NixOS 취약성 분석 및 완화

개요

CVE-2026-84642 is an authorization bypass vulnerability in Mozilla Thunderbird caused by unescaped regular expression handling of the mail.allowed_attachment_hostnames advanced configuration setting. When hostnames configured in this allowlist contain regex metacharacters, they are used directly in a regular expression without proper escaping, allowing certain unintended hostnames to match and serve remote attachments. The vulnerability affects Thunderbird versions prior to 155.0 (in the 154.x branch) and prior to 153.2.0 (in the ESR branch), and was disclosed on September 1, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Mozilla MFSA2026-86, Mozilla MFSA2026-88).

기술적 세부 사항

The root cause is classified as CWE-1333 (Inefficient Regular Expression Complexity) and maps to CAPEC-492 (Regular Expression Exponential Blowup), reflecting improper handling of user-supplied input in regex construction. Thunderbird's attachment hostname allowlist feature reads values from mail.allowed_attachment_hostnames and incorporates them directly into a regular expression pattern without escaping special regex metacharacters. For hostnames that happen to contain characters with regex significance (e.g., ., *, +), the resulting pattern can inadvertently match additional, unintended hostnames, bypassing the intended access restriction. This is a network-accessible flaw requiring no authentication or user interaction, as the matching occurs automatically when remote attachments are processed (Mozilla MFSA2026-86, Mozilla MFSA2026-88).

영향

Successful exploitation allows an unauthenticated remote attacker to serve remote attachments from hostnames that should be blocked by the configured allowlist, effectively bypassing Thunderbird's attachment hostname restriction. The primary impact is a high confidentiality risk — users may unknowingly load or interact with remote content from unauthorized sources — while integrity and availability are not directly affected. The scope is limited to Thunderbird clients with a non-empty mail.allowed_attachment_hostnames configuration containing hostnames with regex-special characters (Mozilla MFSA2026-86, Mozilla MFSA2026-88).

악용 가능성

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The vulnerability is automatable (per NVD SSVC assessment) but has only partial technical impact. The EPSS score is approximately 0.148%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.

완화 및 해결 방법

Mozilla has released patches addressing this vulnerability in Thunderbird 155 and Thunderbird ESR 153.2, both announced on September 1, 2026. Users should update to one of these versions immediately via the built-in updater or their platform's package manager. As an additional precaution, administrators should review the mail.allowed_attachment_hostnames setting in Thunderbird's advanced configuration (about:config) to ensure it contains only intended, properly formatted hostnames, and consider clearing or restricting this setting if remote attachment functionality is not required (Mozilla MFSA2026-86, Mozilla MFSA2026-88).

커뮤니티 반응

Mozilla rated the impact of CVE-2026-84642 as "low" within the broader Thunderbird 155 and 153.2 security advisories, which collectively addressed numerous higher-severity issues. The vulnerability was reported by researchers ChinhNguyen and Lowk3yz. No significant independent researcher commentary, media coverage, or notable community discussion specific to this CVE has been identified beyond standard vulnerability aggregator coverage (Mozilla MFSA2026-86, Mozilla MFSA2026-88).

추가 자료

리눅스 배포판 수정 현황

주요 리눅스 배포판과 그 릴리스 전반에 걸친 가용성을 수정하세요.

Debian

수정됨

bookworm

thunderbird

수정됨

sid

thunderbird

수정됨

trixie

thunderbird

수정됨

Ubuntu

알 수 없음

devel

thunderbird

알 수 없음

jammy

thunderbird

알 수 없음

noble

thunderbird

알 수 없음

resolute

thunderbird

알 수 없음

Alpine

영향을 받은 사람들

edge

68.5.0-r0

영향을 받은 사람들

v3.24

151.0.1-r0

영향을 받은 사람들

근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 NixOS 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • headlamp-fips
아니요Sep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • argo-workflows-3.7
아니요Sep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
아니요Sep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
아니요Sep 01, 2026
CVE-2026-32773MEDIUM6.1
  • NixOS logoNixOS
  • spark
아니요Sep 02, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자