CVE-2026-84642
NixOS Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-84642 is an authorization bypass vulnerability in Mozilla Thunderbird caused by unescaped regular expression handling of the mail.allowed_attachment_hostnames advanced configuration setting. When hostnames configured in this allowlist contain regex metacharacters, they are used directly in a regular expression without proper escaping, allowing certain unintended hostnames to match and serve remote attachments. The vulnerability affects Thunderbird versions prior to 155.0 (in the 154.x branch) and prior to 153.2.0 (in the ESR branch), and was disclosed on September 1, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Mozilla MFSA2026-86, Mozilla MFSA2026-88).

Detalhes técnicos

The root cause is classified as CWE-1333 (Inefficient Regular Expression Complexity) and maps to CAPEC-492 (Regular Expression Exponential Blowup), reflecting improper handling of user-supplied input in regex construction. Thunderbird's attachment hostname allowlist feature reads values from mail.allowed_attachment_hostnames and incorporates them directly into a regular expression pattern without escaping special regex metacharacters. For hostnames that happen to contain characters with regex significance (e.g., ., *, +), the resulting pattern can inadvertently match additional, unintended hostnames, bypassing the intended access restriction. This is a network-accessible flaw requiring no authentication or user interaction, as the matching occurs automatically when remote attachments are processed (Mozilla MFSA2026-86, Mozilla MFSA2026-88).

Impacto

Successful exploitation allows an unauthenticated remote attacker to serve remote attachments from hostnames that should be blocked by the configured allowlist, effectively bypassing Thunderbird's attachment hostname restriction. The primary impact is a high confidentiality risk — users may unknowingly load or interact with remote content from unauthorized sources — while integrity and availability are not directly affected. The scope is limited to Thunderbird clients with a non-empty mail.allowed_attachment_hostnames configuration containing hostnames with regex-special characters (Mozilla MFSA2026-86, Mozilla MFSA2026-88).

Exploração

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The vulnerability is automatable (per NVD SSVC assessment) but has only partial technical impact. The EPSS score is approximately 0.148%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.

Mitigação e soluções alternativas

Mozilla has released patches addressing this vulnerability in Thunderbird 155 and Thunderbird ESR 153.2, both announced on September 1, 2026. Users should update to one of these versions immediately via the built-in updater or their platform's package manager. As an additional precaution, administrators should review the mail.allowed_attachment_hostnames setting in Thunderbird's advanced configuration (about:config) to ensure it contains only intended, properly formatted hostnames, and consider clearing or restricting this setting if remote attachment functionality is not required (Mozilla MFSA2026-86, Mozilla MFSA2026-88).

Reações da comunidade

Mozilla rated the impact of CVE-2026-84642 as "low" within the broader Thunderbird 155 and 153.2 security advisories, which collectively addressed numerous higher-severity issues. The vulnerability was reported by researchers ChinhNguyen and Lowk3yz. No significant independent researcher commentary, media coverage, or notable community discussion specific to this CVE has been identified beyond standard vulnerability aggregator coverage (Mozilla MFSA2026-86, Mozilla MFSA2026-88).

Recursos adicionais

Status correto da distribuição Linux

Disponibilidade de correção em distribuições Linux principais e suas versões.

Debian

Fixo

bookworm

thunderbird

Fixo

sid

thunderbird

Fixo

trixie

thunderbird

Fixo

Ubuntu

Desconhecido

devel

thunderbird

Desconhecido

jammy

thunderbird

Desconhecido

noble

thunderbird

Desconhecido

resolute

thunderbird

Desconhecido

Alpine

Afetados

edge

68.5.0-r0

Afetados

v3.24

151.0.1-r0

Afetados

OrigemEste relatório foi gerado usando IA

Relacionado NixOS Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • headlamp-fips
NãoSimSep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • argo-workflows-3.7
NãoSimSep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NãoSimSep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NãoSimSep 01, 2026
CVE-2026-32773MEDIUM6.1
  • NixOS logoNixOS
  • spark
NãoSimSep 02, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades