CVE-2025-4086Medium· 6.5▾ SunlitA specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Thunderbird for Android. Other versions of Thunderbird …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
firefox < 138.0thunderbird < 138.0Upgrade past the affected range:
firefox 138.0thunderbird 138.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92069Medium· 5.4Spoofing issue in the DOM: Navigation component
CVE-2026-8964High· 7.5Spoofing issue in the Popup Blocker component
CVE-2026-96869Medium· 4.3Information disclosure in the Networking component
CVE-2026-100832High· 8.8Use-after-free in the Graphics: Canvas2D component
CVE-2026-100831High· 8.8Use-after-free in the DOM: UI Events & Focus Handling component
CVE-2026-100830NoneMitigation bypass in the DOM: Navigation component