CVE-2025-8032

XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*

History

13 Apr 2026, 15:17

Type Values Removed Values Added
Summary (en) XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. (en) XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.

03 Nov 2025, 20:19

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/07/msg00016.html -

28 Jul 2025, 18:40

Type Values Removed Values Added
First Time Mozilla
Mozilla firefox
Mozilla thunderbird
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1974407 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1974407 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-56/ - () https://www.mozilla.org/security/advisories/mfsa2025-56/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-58/ - () https://www.mozilla.org/security/advisories/mfsa2025-58/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-59/ - () https://www.mozilla.org/security/advisories/mfsa2025-59/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-61/ - () https://www.mozilla.org/security/advisories/mfsa2025-61/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-62/ - () https://www.mozilla.org/security/advisories/mfsa2025-62/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-63/ - () https://www.mozilla.org/security/advisories/mfsa2025-63/ - Vendor Advisory

23 Jul 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CWE CWE-693
Summary
  • (es) La carga de documentos XSLT no propagó correctamente el documento fuente, lo que eludió su CSP. Esta vulnerabilidad afecta a Firefox &lt; 141, Firefox ESR &lt; 128.13, Firefox ESR &lt; 140.1, Thunderbird &lt; 141, Thunderbird &lt; 128.13 y Thunderbird &lt; 140.1.

22 Jul 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-22 21:15

Updated : 2026-04-13 15:17


NVD link : CVE-2025-8032

Mitre link : CVE-2025-8032

CVE.ORG link : CVE-2025-8032


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
CWE
CWE-693

Protection Mechanism Failure