CVE-2025-0239

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

13 Apr 2026, 15:16

Type Values Removed Values Added
Summary (en) When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6. (en) When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

03 Nov 2025, 23:17

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/01/msg00004.html -

03 Apr 2025, 16:29

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1929156 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1929156 - Issue Tracking, Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-01/ - () https://www.mozilla.org/security/advisories/mfsa2025-01/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-02/ - () https://www.mozilla.org/security/advisories/mfsa2025-02/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-04/ - () https://www.mozilla.org/security/advisories/mfsa2025-04/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-05/ - () https://www.mozilla.org/security/advisories/mfsa2025-05/ - Vendor Advisory
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
First Time Mozilla firefox
Mozilla thunderbird
Mozilla

13 Jan 2025, 22:15

Type Values Removed Values Added
Summary (en) When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird ESR < 128.6. (en) When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

09 Jan 2025, 09:15

Type Values Removed Values Added
References
  • () https://www.mozilla.org/security/advisories/mfsa2025-04/ -
  • () https://www.mozilla.org/security/advisories/mfsa2025-05/ -
Summary (en) When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6. (en) When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird ESR < 128.6.

08 Jan 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.0
Summary
  • (es) Al utilizar Alt-Svc, ALPN no validó correctamente los certificados cuando el servidor original redireccionaba a un sitio inseguro. Esta vulnerabilidad afecta a Firefox &lt; 134 y Firefox ESR &lt; 128.6.
CWE CWE-295

07 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-07 16:15

Updated : 2026-04-13 15:16


NVD link : CVE-2025-0239

Mitre link : CVE-2025-0239

CVE.ORG link : CVE-2025-0239


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
CWE
CWE-295

Improper Certificate Validation