CVE-2025-0239

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

13 Apr 2026, 15:16

Type Values Removed Values Added
Summary (en) When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6. (en) When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

03 Nov 2025, 23:17

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/01/msg00004.html -

03 Apr 2025, 16:29

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1929156 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1929156 - Issue Tracking, Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-01/ - () https://www.mozilla.org/security/advisories/mfsa2025-01/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-02/ - () https://www.mozilla.org/security/advisories/mfsa2025-02/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-04/ - () https://www.mozilla.org/security/advisories/mfsa2025-04/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-05/ - () https://www.mozilla.org/security/advisories/mfsa2025-05/ - Vendor Advisory
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
First Time Mozilla firefox
Mozilla thunderbird
Mozilla

13 Jan 2025, 22:15

Type Values Removed Values Added
Summary (en) When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird ESR < 128.6. (en) When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

09 Jan 2025, 09:15

Type Values Removed Values Added
References
  • () https://www.mozilla.org/security/advisories/mfsa2025-04/ -
  • () https://www.mozilla.org/security/advisories/mfsa2025-05/ -
Summary (en) When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6. (en) When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird ESR < 128.6.

08 Jan 2025, 17:15

Type Values Removed Values Added
CWE CWE-295
Summary
  • (es) Al utilizar Alt-Svc, ALPN no validó correctamente los certificados cuando el servidor original redireccionaba a un sitio inseguro. Esta vulnerabilidad afecta a Firefox &lt; 134 y Firefox ESR &lt; 128.6.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.0

07 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-07 16:15

Updated : 2026-06-17 08:26


NVD link : CVE-2025-0239

Mitre link : CVE-2025-0239

CVE.ORG link : CVE-2025-0239


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird
CWE
CWE-295

Improper Certificate Validation