CVE detail
CVE-2021-23991 — CVE-2021-23991
Published 2021-06-24 · Modified 2026-06-17 · Vendor mozilla · Product thunderbird · Source nvd
MEDIUM
severity
CVSS-derived band
0.0103
EPSS probability
exploitation probability, 30d
61.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References