Loading HuntDB...

GHSA-c839-4fpv-9xp7

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulnerability affects Thunderbird < 78.7.

Related CVEs

Key Information

GHSA ID
GHSA-c839-4fpv-9xp7
Published
December 22, 2022 9:30 PM
Last Modified
April 16, 2025 3:34 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: November 26, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.