CVE-2026-0818Disclosure(mozilla / thunderbird)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mozilla thunderbird systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled with HTML and CSS, then the decrypted contents were rendered in a context in which the CSS styles from the outer messages were active. If the user had additionally allowed loading of the remote content referenced by the outer email message, and the email was crafted by the sender using a combination of CSS rules and fonts and animations, then it was possible to extract the secret contents of the email. This vulnerability was fixed in Thunderbird 147.0.1 and Thunderbird 140.7.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-116CWE-200CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • thunderbird

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
thunderbird

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-28: 2Mentions · 2026-02-06: 1Patch / Workaround · 2026-02-06: 1Technical Details · 2026-01-28: 1Technical Details · 2026-02-06: 101-2802-06
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-282
Disclosure1General1
2026-02-061
Patch1
Full discourse3 posts
  • ThreatCluster@threatcluster
    Patch

    Mozilla Thunderbird fixes CVE-2026-0818, a CSS-based exfiltration bug that could leak content from partially encrypted emails when remote content is allowed. Update to version 140.7.1. https://threatcluster.io/cluster/mozilla-thunderbird-css-exfiltration-vulnerability-patched-c06ec952

    Post summary

    Mozilla Thunderbird released patch 140.7.1 to address CVE-2026-0818, a CSS-based exfiltration vulnerability that could leak content from partially encrypted emails when remote content is permitted.

    0000059
    80 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-0818 CSS-Based Content Exfiltration Vulnerability in Thunderbird Email Client https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0818

    Post summary

    The entry merely identifies CVE-2026-0818 as a CSS‑based content exfiltration vulnerability in Thunderbird, with no further technical, exploit, or mitigation details provided.

    0000043
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0818 CSS-based exfiltration of the content from partially encrypted emails when allowing remote content. This vulnerability affects Thunderbird < 147.0.1 and Thunderbird < 1… https://www.cve.org/CVERecord?id=CVE-2026-0818

    Post summary

    The post announces CVE‑2026‑0818, outlining its CSS‑based exfiltration mechanism in Thunderbird’s partially encrypted emails and identifying affected versions.

    00000192
    56.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillathunderbird---
Appmozillathunderbird---

Explore more