A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 7.9%