CVE-2025-8031

CRITICAL

Firefox and Thunderbird - HTTP Basic Authentication Credential Leak via CSP Report URL Handling

Title source: llm
STIX 2.1

Description

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.

Scores

CVSS v3 9.8
EPSS 0.0042
EPSS Percentile 33.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-276
Status published
Products (10)
mozilla/firefox < 128.13.0
mozilla/firefox < 141.0
Mozilla/Firefox 128.13 - 128.*
Mozilla/Firefox 140.1 - 140.*
Mozilla/Firefox 141
mozilla/thunderbird < 128.13.0
mozilla/thunderbird < 141.0
Mozilla/Thunderbird 128.13 - 128.*
Mozilla/Thunderbird 140.1 - 140.*
Mozilla/Thunderbird 141
Published Jul 22, 2025
Tracked Since Feb 18, 2026