CVE-2025-26696

Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being encrypted. This vulnerability affects Thunderbird < 136 and Thunderbird < 128.8.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

03 Apr 2025, 13:30

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1864205 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1864205 - Issue Tracking
References () https://www.mozilla.org/security/advisories/mfsa2025-17/ - () https://www.mozilla.org/security/advisories/mfsa2025-17/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-18/ - () https://www.mozilla.org/security/advisories/mfsa2025-18/ - Vendor Advisory
CPE cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
First Time Mozilla
Mozilla thunderbird

11 Mar 2025, 20:15

Type Values Removed Values Added
CWE CWE-290
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.0
Summary
  • (es) Algunos mensajes de correo electrónico con MIME manipulados a medida que afirmaban contener un mensaje OpenPGP cifrado, cuando en realidad contenían un mensaje firmado con OpenPGP, se mostraban erróneamente como cifrados. Esta vulnerabilidad afecta a Thunderbird &lt; 136 y Thunderbird &lt; 128.8.

10 Mar 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-10 19:15

Updated : 2025-04-03 13:30


NVD link : CVE-2025-26696

Mitre link : CVE-2025-26696

CVE.ORG link : CVE-2025-26696


JSON object : View

Products Affected

mozilla

  • thunderbird
CWE
CWE-290

Authentication Bypass by Spoofing