CVE-2025-8036

Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*

History

13 Apr 2026, 15:17

Type Values Removed Values Added
Summary (en) Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1. (en) Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.

03 Nov 2025, 18:17

Type Values Removed Values Added
References
  • () https://www.kb.cert.org/vuls/id/652514 -

09 Sep 2025, 07:15

Type Values Removed Values Added
Summary (en) Firefox cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1. (en) Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

30 Jul 2025, 17:15

Type Values Removed Values Added
Summary (en) Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1. (en) Firefox cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

28 Jul 2025, 18:49

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1960834 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1960834 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-56/ - () https://www.mozilla.org/security/advisories/mfsa2025-56/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-59/ - () https://www.mozilla.org/security/advisories/mfsa2025-59/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-61/ - () https://www.mozilla.org/security/advisories/mfsa2025-61/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-63/ - () https://www.mozilla.org/security/advisories/mfsa2025-63/ - Vendor Advisory
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
First Time Mozilla
Mozilla firefox
Mozilla thunderbird

23 Jul 2025, 15:15

Type Values Removed Values Added
Summary
  • (es) Thunderbird almacenó en caché las respuestas de preflight de CORS tras los cambios de dirección IP. Esto permitió eludir CORS mediante revinculación de DNS. Esta vulnerabilidad afecta a Firefox &lt; 141, Firefox ESR &lt; 140.1, Thunderbird &lt; 141 y Thunderbird &lt; 140.1.
CWE CWE-350
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

22 Jul 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-22 21:15

Updated : 2026-04-13 15:17


NVD link : CVE-2025-8036

Mitre link : CVE-2025-8036

CVE.ORG link : CVE-2025-8036


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
CWE
CWE-350

Reliance on Reverse DNS Resolution for a Security-Critical Action