Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being encrypted. This vulnerability was fixed in Thunderbird 136 and Thunderbird 128.8.
Metrics
Affected Vendors & Products
References
History
Mon, 13 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being encrypted. This vulnerability affects Thunderbird < 136 and Thunderbird < 128.8. | Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being encrypted. This vulnerability was fixed in Thunderbird 136 and Thunderbird 128.8. |
| Title | thunderbird: Crafted email message incorrectly shown as being encrypted | Crafted email message incorrectly shown as being encrypted |
Thu, 03 Apr 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla thunderbird |
|
| CPEs | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mozilla
Mozilla thunderbird |
Thu, 13 Mar 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | thunderbird: Crafted email message incorrectly shown as being encrypted | |
| Weaknesses | CWE-451 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 11 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-290 | |
| Metrics |
cvssV3_1
|
Mon, 10 Mar 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being encrypted. This vulnerability affects Thunderbird < 136 and Thunderbird < 128.8. | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-04-13T14:27:27.799Z
Reserved: 2025-02-13T22:03:43.233Z
Link: CVE-2025-26696
Updated: 2025-03-11T19:16:58.244Z
Status : Modified
Published: 2025-03-10T19:15:40.670
Modified: 2026-04-13T15:16:54.973
Link: CVE-2025-26696