When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
References
| Link | Resource |
|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=1929156 | Issue Tracking Permissions Required |
| https://www.mozilla.org/security/advisories/mfsa2025-01/ | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-02/ | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-04/ | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-05/ | Vendor Advisory |
| https://lists.debian.org/debian-lts-announce/2025/01/msg00004.html |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-01-07 16:15
Updated : 2026-06-17 08:26
NVD link : CVE-2025-0239
Mitre link : CVE-2025-0239
CVE.ORG link : CVE-2025-0239
JSON object : View
Products Affected
mozilla
- thunderbird
- firefox
CWE
CWE-295
Improper Certificate Validation
