CVE-2026-84640
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-84640 is a one-byte out-of-bounds read vulnerability in Mozilla Thunderbird's mail parser, described as "One byte overflow read in mail parser." A maliciously constructed mail header can trigger a one-byte read past the end of a buffer during mail header processing. The vulnerability affects Mozilla Thunderbird prior to versions 155, 140.15 (ESR), and 153.2 (ESR), and was disclosed on September 1, 2026. It was reported by Ramesh Adhikari and Dr. Faruk Kazi of CoE-CNDS Lab, VJTI, Mumbai, India. Mozilla rates the impact as medium (Mozilla MFSA2026-86, Mozilla MFSA2026-87, Mozilla MFSA2026-88).

Technical details

The root cause is an off-by-one buffer over-read (CWE-125) in Thunderbird's mail header parsing logic. When processing a specially crafted mail header, the parser reads one byte beyond the allocated buffer boundary, constituting a memory disclosure condition. The attack vector is network-based and requires no authentication — an attacker simply sends a crafted email to a target Thunderbird user. Mozilla notes that in general these flaws cannot be exploited through email in Thunderbird because scripting is disabled when reading mail, but they may present risks in browser or browser-like contexts (Mozilla MFSA2026-86, Mozilla MFSA2026-87).

Impact

Successful exploitation allows an unauthenticated attacker to read one byte of memory beyond the intended buffer boundary, resulting in a limited memory disclosure. The primary impact is on confidentiality; integrity and availability are not directly affected by this vulnerability. While the single-byte read limits the scope of data exposure, such out-of-bounds reads can in some contexts leak sensitive in-memory data or contribute to information leakage that aids further exploitation (Mozilla MFSA2026-86, Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Feedly). The EPSS score is reported as 0.0, indicating very low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Mitigation and workarounds

Mozilla has released patches addressing CVE-2026-84640 in the following versions: Thunderbird 155, Thunderbird ESR 140.15, and Thunderbird ESR 153.2, all announced September 1, 2026. Users should update to one of these patched releases as soon as possible. No configuration-based workarounds have been published; upgrading is the recommended and only confirmed remediation (Mozilla MFSA2026-86, Mozilla MFSA2026-87, Mozilla MFSA2026-88).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78662HIGH7.5
  • Terraform Community logoTerraform Community
  • argo-workflow-controller-fips-4.0
NoYesSep 02, 2026
CVE-2026-56855HIGH7.5
  • Terraform Community logoTerraform Community
  • prometheus-mongodb-exporter-0.37
NoYesSep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-84640HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management