Mozilla Thunderbird OpenPGP Key Request Padding Size Vulnerability

Vulnerability

A vulnerability exists in Mozilla Thunderbird versions prior to 136 and prior to 128.8, where an incorrect padding size was used when requesting OpenPGP keys from a WKD server. This flaw allowed a network observer to infer the length of the email address being requested.

Impact

Exploitation of this vulnerability could lead to the disclosure of the length of the requested email address to a network observer.

Remediation

Users can upgrade to Thunderbird 136 or Thunderbird 128.8 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
4.7
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.