What is CVE-2026-14899?
An off-by-one error was discovered in Thunderbird's code for parsing MIME headers when forwarding a message with the 'view all headers' setting enabled. This vulnerability could allow a single byte to be read from memory after the header buffer, potentially causing Thunderbird to crash. Users are strongly advised to apply the latest Thunderbird update that addresses this fix immediately.
Azərbaycanca: Thunderbird-də bütün başlıqları göstərmək seçimi aktiv olduqda, mesajı yönləndirmək üçün MIME başlıqlarını təhlil edən kodda off-by-one səhvi aşkar edilib. Bu zəiflik yaddaşda başlıq buferindən sonrakı bir baytın oxunmasına və potensial olaraq Thunderbird-in çökməsinə səbəb ola bilər. İstifadəçilərə təcili olaraq bu zəifliyin aradan qaldırıldığı son Thunderbird yeniləməsini tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Under what conditions is CVE-2026-14899 triggered in Thunderbird?
This vulnerability is triggered when the 'view all headers' setting is enabled in Thunderbird and an off-by-one error occurs in the code that parses MIME headers while forwarding a message.
What are the potential consequences of exploiting CVE-2026-14899?
Exploiting this vulnerability could allow a single byte to be read from memory after the header buffer, potentially causing Thunderbird to crash.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.