CVE-2025-26695: Downloading of OpenPGP keys from WKD used incorrect padding
When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested email address.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 136 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 128.8 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 136 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 128.8
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-26695?
CVE-2025-26695 is considered a medium severity vulnerability due to the potential exposure of email address lengths to an attacker.
How do I fix CVE-2025-26695?
To fix CVE-2025-26695, upgrade to Thunderbird version 136 or later, or version 128.8 or later.
What versions of Thunderbird are affected by CVE-2025-26695?
CVE-2025-26695 affects versions of Thunderbird prior to 136 and prior to 128.8.
What is the impact of CVE-2025-26695 on user privacy?
The impact of CVE-2025-26695 is that a network observer could potentially learn the length of the requested email address, compromising user privacy.
When was CVE-2025-26695 reported?
CVE-2025-26695 was reported as part of security advisories for Mozilla Thunderbird in 2025.