CVE 9.8 CRITICAL

CVE-2025-8031_CVE-2025-8031

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.

Basic Information

ID CVE-2025-8031
Source mozilla
Published Jul 22, 2025 at 20:49
Modified Jul 23, 2025 at 14:00

Affected Product

Vendor Mozilla
Product Firefox
Version unspecified
Affected Versions Mozilla Firefox unspecified
Mozilla Firefox ESR unspecified
Mozilla Firefox ESR unspecified
Mozilla Thunderbird unspecified
Mozilla Thunderbird unspecified
Mozilla Thunderbird unspecified

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.