---
id: CVE-2026-103500
title: >-
  An attacker could cause a heap buffer overflow by getting a user to open an
  email that is greater than or equal to 2GB in size
summary: >-
  An attacker could cause a heap buffer overflow by getting a user to open an
  email that is greater than or equal to 2GB in size. This vulnerability was
  fixed in Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4.
severity: none
vendor: Mozilla
product: Thunderbird
affected:
  - Thunderbird
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T19:05:23.307'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103500'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=2070267'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2026-101/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2026-102/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2026-103/'
    label: security@mozilla.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T18:17:24.565Z'
---

## Overview

An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
