CVE-2025-6432

HIGH

Firefox < 140.0 - DNS Proxy Bypass via Invalid Domain or Unresponsive SOCKS Proxy

Title source: llm
STIX 2.1

Description

When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

Scores

CVSS v3 8.6
EPSS 0.0041
EPSS Percentile 61.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (3)
mozilla/firefox < 140.0
Mozilla/Firefox 140
Mozilla/Thunderbird 140
Published Jun 24, 2025
Tracked Since Feb 18, 2026