An attacker may use Thunderbird's OpenPGP key refresh mechanism to poison an existing key (CVE-2021-23991).
A crafted OpenPGP key with an invalid user ID could be used to confuse the user (CVE-2021-23992).
Inability to send encrypted OpenPGP email after importing a crafted OpenPGP key (CVE-2021-23993).