CVE-2025-26695

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Mar 10, 2025
Updated: Apr 3, 2025

Summary

CVE-2025-26695 is a vulnerability affecting Thunderbird versions 135 and older, as well as Thunderbird 128.8 and below. This issue stems from an incorrect padding size utilized when requesting an OpenPGP key from a WKD (Web Key Directory) server. Consequently, a network observer could potentially discern the length of the targeted email address, posing a privacy concern.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share