Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-26695


When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested email address. This vulnerability affects Thunderbird < 136 and Thunderbird < 128.8.


Published

2025-03-10T19:15:40.567

Last Modified

2025-04-03T13:30:39.037

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mozilla thunderbird < 128.8.0 Yes
Application mozilla thunderbird < 136.0 Yes

References