CVE-2025-26695: Downloading of OpenPGP keys from WKD used incorrect padding
When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested email address.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-26695?
CVE-2025-26695 is considered a medium severity vulnerability due to the potential exposure of email address lengths to an attacker.
How do I fix CVE-2025-26695?
To fix CVE-2025-26695, upgrade to Thunderbird version 136 or later, or version 128.8 or later.
What versions of Thunderbird are affected by CVE-2025-26695?
CVE-2025-26695 affects versions of Thunderbird prior to 136 and prior to 128.8.
What is the impact of CVE-2025-26695 on user privacy?
The impact of CVE-2025-26695 is that a network observer could potentially learn the length of the requested email address, compromising user privacy.
When was CVE-2025-26695 reported?
CVE-2025-26695 was reported as part of security advisories for Mozilla Thunderbird in 2025.