CVE-2025-8031
Last modified
CVE-2025-8031 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 128.13.0 |
| Mozilla | Firefox | < 141.0 |
| Mozilla | Firefox | >= 140.0, < 140.1.0 |
| Mozilla | Thunderbird | < 128.13.0 |
| Mozilla | Thunderbird | < 141.0 |
| Mozilla | Thunderbird | >= 140.0, < 140.1.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1971719Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2025-56/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-58/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-59/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-61/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-62/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-63/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-8031?
How severe is CVE-2025-8031?
How do I fix CVE-2025-8031?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-8023Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11…4.9
- CVE-2025-8025Missing Authentication for Critical Function, Improper Acces…9.8
- CVE-2025-8027On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the …6.5
- CVE-2025-8028On arm64, a WASM `br_table` instruction with a lot of entrie…9.8
- CVE-2025-8029Thunderbird executed `javascript:` URLs when used in `object…8.1
- CVE-2025-8030Insufficient escaping in the “Copy as cURL” feature could po…8.1
- CVE-2025-8032XSLT document loading did not correctly propagate the source…8.1
- CVE-2025-8033The JavaScript engine did not handle closed generators corre…6.5
- CVE-2025-8034Memory safety bugs present in Firefox ESR 115.25, Firefox ES…8.8
- CVE-2025-8035Memory safety bugs present in Firefox ESR 128.12, Thunderbir…8.8
- CVE-2025-8036Thunderbird cached CORS preflight responses across IP addres…8.1
- CVE-2025-8037Setting a nameless cookie with an equals sign in the value s…9.1
Are you affected by CVE-2025-8031?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
