CVE-2026-14899: Off-by-one out of bounds read in MIME header parser for forwarding
The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 153 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.13
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-14899
- CVE-2026-15718
- CVE-2026-15719
- CVE-2026-16349
- CVE-2026-16350
- CVE-2026-16362
- CVE-2026-16351
- CVE-2026-16352
- CVE-2026-16363
- CVE-2026-16353
- CVE-2026-16354
- CVE-2026-16368
- CVE-2026-16369
- CVE-2026-16355
- CVE-2026-16356
- CVE-2026-16357
- CVE-2026-16371
- CVE-2026-16374
- CVE-2026-16375
- CVE-2026-16377
- CVE-2026-16379
- CVE-2026-16358
- CVE-2026-16381
- CVE-2026-16383
- CVE-2026-16387
- CVE-2026-16390
- CVE-2026-16391
- CVE-2026-16359
- CVE-2026-16396
- CVE-2026-16405
- CVE-2026-16412
- CVE-2026-16360
- CVE-2026-16361
- CVE-2026-16364
- CVE-2026-16365
- CVE-2026-16366
- CVE-2026-16367
- CVE-2026-16370
- CVE-2026-16372
- CVE-2026-16376
- CVE-2026-16378
- CVE-2026-16380
- CVE-2026-16382
- CVE-2026-16384
- CVE-2026-16385
- CVE-2026-16386
- CVE-2026-16388
- CVE-2026-16389
- CVE-2026-16392
- CVE-2026-16393
- CVE-2026-16394
- CVE-2026-16395
- CVE-2026-16398
- CVE-2026-16399
- CVE-2026-16400
- CVE-2026-16401
- CVE-2026-16402
- CVE-2026-16403
- CVE-2026-16406
- CVE-2026-16407
- CVE-2026-16408
- CVE-2026-16409
- CVE-2026-16410
- CVE-2026-16411
Frequently Asked Questions
What is the severity of CVE-2026-14899?
CVE-2026-14899 has a severity rating of 10, indicating it is critical.
How do I fix CVE-2026-14899?
To fix CVE-2026-14899, update Mozilla Thunderbird to the latest version that contains the patch.
What are the potential impacts of CVE-2026-14899?
CVE-2026-14899 could lead to a crash of Mozilla Thunderbird due to an out of bounds read.
Who is affected by CVE-2026-14899?
Users of Mozilla Thunderbird with the setting to view all headers enabled are affected by CVE-2026-14899.
When was CVE-2026-14899 published?
CVE-2026-14899 was published on July 22, 2026.