firefox: thunderbird: XSLT documents could bypass CSP
cve CVE-2025-8032 2 sources, 2 claims · Watch
What it is to other things
| affects | mozilla/firefox NVD |
| affects | mozilla/thunderbird NVD |
| made_by | mozilla NVD |
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Cvss cvss conflict | NVD | 8.1receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Firefox",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.13",
"versionType": "rpm"
},
{
"lessThanOrEqual": "140.*",
"status": "unaffected",
"version": "140.1",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "141",
"versionType": "rpm"
}
]
},
{
"product": "Thunderbird",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.13",
"versionType": "rpm"
},
{
"lessThanOrEqual": "140.*",
"status": "unaffected",
"version": "140.1",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "141",
"versionType": "rpm"
}
]
}
],
"source": "security@mozilla.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "7C22C9BA-7B86-487A-B0A4-419A0D163B56",
"versionEndExcluding": "128.13.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
"matchCriteriaId": "8684A46E-D70A-4830-8971-A6DCC360F422",
"versionEndExcluding": "141.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "BB48C2EF-A6AC-4445-9417-1B65D5BC509B",
"versionEndExcluding": "140.1.0",
"versionStartIncluding": "140.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "B9BB9B0C-2B49-44EA-9BED-241A8CE8794E",
"versionEndExcluding": "128.13.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*",
"matchCriteriaId": "95D506DD-BD9B-4D90-802F-5BE673F1CF14",
"versionEndExcluding": "141.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "8CE266C2-5AF1-4C57-9B7C-47039FF06384",
"versionEndExcluding": "140.1.0",
"versionStartIncluding": "140.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1."
},
{
"lang": "es",
"value": "La carga de documentos XSLT no propagó correctamente el documento fuente, lo que eludió su CSP. Esta vulnerabilidad afecta a Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13 y Thunderbird < 140.1."
}
],
"id": "CVE-2025-8032",
"lastModified": "2026-09-30T18:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.2,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-8032",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-07-23T13:55:17.746727Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-07-22T21:15:50.360",
"references": [
{
"source": "security@mozilla.org",
"tags": [
"Permissions Required"
],
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1974407"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-56/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-58/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-59/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-61/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-62/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-63/"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "https://lists.debian.org/debian-lts-announce/2025/07/msg00016.html"
}
],
"sourceIdentifier": "security@mozilla.org",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-693"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Cvss cvss conflict | Red Hat | 6.1receipt
What the source handed over{
"CVE": "CVE-2025-8032",
"CWE": "CWE-693",
"advisories": [
"RHSA-2025:13648",
"RHSA-2025:13647",
"RHSA-2025:11797",
"RHSA-2025:13646",
"RHSA-2025:13645",
"RHSA-2025:12302",
"RHSA-2025:13676",
"RHSA-2025:12278",
"RHSA-2025:12046",
"RHSA-2025:11748",
"RHSA-2025:11747",
"RHSA-2025:13649",
"RHSA-2025:12188",
"RHSA-2025:12353",
"RHSA-2025:13651",
"RHSA-2025:12045",
"RHSA-2025:13650",
"RHSA-2025:12187",
"RHSA-2025:12044",
"RHSA-2025:12361",
"RHSA-2025:12360"
],
"affected_packages": [
"firefox-0:128.13.0-1.el10_0",
"firefox-0:128.13.0-1.el7_9",
"firefox-0:128.13.0-1.el8_8",
"thunderbird-0:128.13.0-3.el9_0",
"firefox-0:128.13.0-1.el8_6",
"firefox-0:128.13.0-1.el9_6",
"thunderbird-0:128.13.0-3.el10_0",
"firefox-0:128.13.0-1.el8_4",
"firefox-0:128.13.0-1.el9_4",
"firefox-0:128.13.0-1.el8_2",
"firefox-0:128.13.0-1.el9_2",
"firefox-0:128.13.0-1.el9_0",
"firefox-0:128.13.0-1.el8_10",
"thunderbird-0:128.13.0-3.el8_10",
"thunderbird-0:128.13.0-3.el9_2",
"thunderbird-0:128.13.0-3.el8_2",
"thunderbird-0:128.13.0-3.el9_4",
"thunderbird-0:128.13.0-3.el8_4",
"thunderbird-0:128.13.0-3.el9_6",
"thunderbird-0:128.13.0-3.el8_6",
"thunderbird-0:128.13.0-3.el8_8"
],
"bugzilla": "2382718",
"bugzilla_description": "firefox: thunderbird: XSLT documents could bypass CSP",
"cvss3_score": "6.1",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-07-22T20:49:26Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-8032.json",
"severity": "moderate"
} | — |
| Cwe cwe | Red Hat | CWE-693receipt
What the source handed over{
"CVE": "CVE-2025-8032",
"CWE": "CWE-693",
"advisories": [
"RHSA-2025:13648",
"RHSA-2025:13647",
"RHSA-2025:11797",
"RHSA-2025:13646",
"RHSA-2025:13645",
"RHSA-2025:12302",
"RHSA-2025:13676",
"RHSA-2025:12278",
"RHSA-2025:12046",
"RHSA-2025:11748",
"RHSA-2025:11747",
"RHSA-2025:13649",
"RHSA-2025:12188",
"RHSA-2025:12353",
"RHSA-2025:13651",
"RHSA-2025:12045",
"RHSA-2025:13650",
"RHSA-2025:12187",
"RHSA-2025:12044",
"RHSA-2025:12361",
"RHSA-2025:12360"
],
"affected_packages": [
"firefox-0:128.13.0-1.el10_0",
"firefox-0:128.13.0-1.el7_9",
"firefox-0:128.13.0-1.el8_8",
"thunderbird-0:128.13.0-3.el9_0",
"firefox-0:128.13.0-1.el8_6",
"firefox-0:128.13.0-1.el9_6",
"thunderbird-0:128.13.0-3.el10_0",
"firefox-0:128.13.0-1.el8_4",
"firefox-0:128.13.0-1.el9_4",
"firefox-0:128.13.0-1.el8_2",
"firefox-0:128.13.0-1.el9_2",
"firefox-0:128.13.0-1.el9_0",
"firefox-0:128.13.0-1.el8_10",
"thunderbird-0:128.13.0-3.el8_10",
"thunderbird-0:128.13.0-3.el9_2",
"thunderbird-0:128.13.0-3.el8_2",
"thunderbird-0:128.13.0-3.el9_4",
"thunderbird-0:128.13.0-3.el8_4",
"thunderbird-0:128.13.0-3.el9_6",
"thunderbird-0:128.13.0-3.el8_6",
"thunderbird-0:128.13.0-3.el8_8"
],
"bugzilla": "2382718",
"bugzilla_description": "firefox: thunderbird: XSLT documents could bypass CSP",
"cvss3_score": "6.1",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-07-22T20:49:26Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-8032.json",
"severity": "moderate"
} | — |
| Packages packages | Red Hat | firefox-0:128.13.0-1.el10_0, firefox-0:128.13.0-1.el7_9, firefox-0:128.13.0-1.el8_8, thunderbird-0:128.13.0-3.el9_0, firefox-0:128.13.0-1.el8_6, firefox-0:128.13.0-1.el9_6, thunderbird-0:128.13.0-3.el10_0, firefox-0:128.13.0-1.el8_4, firefox-0:128.13.0-1.el9_4, firefox-0:128.13.0-1.el8_2, firefox-0:128.13.0-1.el9_2, firefox-0:128.13.0-1.el9_0, firefox-0:128.13.0-1.el8_10, thunderbird-0:128.13.0-3.el8_10, thunderbird-0:128.13.0-3.el9_2, thunderbird-0:128.13.0-3.el8_2, thunderbird-0:128.13.0-3.el9_4, thunderbird-0:128.13.0-3.el8_4, thunderbird-0:128.13.0-3.el9_6, thunderbird-0:128.13.0-3.el8_6, thunderbird-0:128.13.0-3.el8_8receipt
What the source handed over{
"CVE": "CVE-2025-8032",
"CWE": "CWE-693",
"advisories": [
"RHSA-2025:13648",
"RHSA-2025:13647",
"RHSA-2025:11797",
"RHSA-2025:13646",
"RHSA-2025:13645",
"RHSA-2025:12302",
"RHSA-2025:13676",
"RHSA-2025:12278",
"RHSA-2025:12046",
"RHSA-2025:11748",
"RHSA-2025:11747",
"RHSA-2025:13649",
"RHSA-2025:12188",
"RHSA-2025:12353",
"RHSA-2025:13651",
"RHSA-2025:12045",
"RHSA-2025:13650",
"RHSA-2025:12187",
"RHSA-2025:12044",
"RHSA-2025:12361",
"RHSA-2025:12360"
],
"affected_packages": [
"firefox-0:128.13.0-1.el10_0",
"firefox-0:128.13.0-1.el7_9",
"firefox-0:128.13.0-1.el8_8",
"thunderbird-0:128.13.0-3.el9_0",
"firefox-0:128.13.0-1.el8_6",
"firefox-0:128.13.0-1.el9_6",
"thunderbird-0:128.13.0-3.el10_0",
"firefox-0:128.13.0-1.el8_4",
"firefox-0:128.13.0-1.el9_4",
"firefox-0:128.13.0-1.el8_2",
"firefox-0:128.13.0-1.el9_2",
"firefox-0:128.13.0-1.el9_0",
"firefox-0:128.13.0-1.el8_10",
"thunderbird-0:128.13.0-3.el8_10",
"thunderbird-0:128.13.0-3.el9_2",
"thunderbird-0:128.13.0-3.el8_2",
"thunderbird-0:128.13.0-3.el9_4",
"thunderbird-0:128.13.0-3.el8_4",
"thunderbird-0:128.13.0-3.el9_6",
"thunderbird-0:128.13.0-3.el8_6",
"thunderbird-0:128.13.0-3.el8_8"
],
"bugzilla": "2382718",
"bugzilla_description": "firefox: thunderbird: XSLT documents could bypass CSP",
"cvss3_score": "6.1",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-07-22T20:49:26Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-8032.json",
"severity": "moderate"
} | — |
| Product product | NVD | Firefoxreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Firefox",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.13",
"versionType": "rpm"
},
{
"lessThanOrEqual": "140.*",
"status": "unaffected",
"version": "140.1",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "141",
"versionType": "rpm"
}
]
},
{
"product": "Thunderbird",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.13",
"versionType": "rpm"
},
{
"lessThanOrEqual": "140.*",
"status": "unaffected",
"version": "140.1",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "141",
"versionType": "rpm"
}
]
}
],
"source": "security@mozilla.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "7C22C9BA-7B86-487A-B0A4-419A0D163B56",
"versionEndExcluding": "128.13.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
"matchCriteriaId": "8684A46E-D70A-4830-8971-A6DCC360F422",
"versionEndExcluding": "141.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "BB48C2EF-A6AC-4445-9417-1B65D5BC509B",
"versionEndExcluding": "140.1.0",
"versionStartIncluding": "140.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "B9BB9B0C-2B49-44EA-9BED-241A8CE8794E",
"versionEndExcluding": "128.13.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*",
"matchCriteriaId": "95D506DD-BD9B-4D90-802F-5BE673F1CF14",
"versionEndExcluding": "141.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "8CE266C2-5AF1-4C57-9B7C-47039FF06384",
"versionEndExcluding": "140.1.0",
"versionStartIncluding": "140.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1."
},
{
"lang": "es",
"value": "La carga de documentos XSLT no propagó correctamente el documento fuente, lo que eludió su CSP. Esta vulnerabilidad afecta a Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13 y Thunderbird < 140.1."
}
],
"id": "CVE-2025-8032",
"lastModified": "2026-09-30T18:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.2,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-8032",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-07-23T13:55:17.746727Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-07-22T21:15:50.360",
"references": [
{
"source": "security@mozilla.org",
"tags": [
"Permissions Required"
],
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1974407"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-56/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-58/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-59/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-61/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-62/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-63/"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "https://lists.debian.org/debian-lts-announce/2025/07/msg00016.html"
}
],
"sourceIdentifier": "security@mozilla.org",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-693"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Severity severity | Red Hat | moderate A flaw that is harder to exploit, or whose impact is limited. receipt
What the source handed over{
"CVE": "CVE-2025-8032",
"CWE": "CWE-693",
"advisories": [
"RHSA-2025:13648",
"RHSA-2025:13647",
"RHSA-2025:11797",
"RHSA-2025:13646",
"RHSA-2025:13645",
"RHSA-2025:12302",
"RHSA-2025:13676",
"RHSA-2025:12278",
"RHSA-2025:12046",
"RHSA-2025:11748",
"RHSA-2025:11747",
"RHSA-2025:13649",
"RHSA-2025:12188",
"RHSA-2025:12353",
"RHSA-2025:13651",
"RHSA-2025:12045",
"RHSA-2025:13650",
"RHSA-2025:12187",
"RHSA-2025:12044",
"RHSA-2025:12361",
"RHSA-2025:12360"
],
"affected_packages": [
"firefox-0:128.13.0-1.el10_0",
"firefox-0:128.13.0-1.el7_9",
"firefox-0:128.13.0-1.el8_8",
"thunderbird-0:128.13.0-3.el9_0",
"firefox-0:128.13.0-1.el8_6",
"firefox-0:128.13.0-1.el9_6",
"thunderbird-0:128.13.0-3.el10_0",
"firefox-0:128.13.0-1.el8_4",
"firefox-0:128.13.0-1.el9_4",
"firefox-0:128.13.0-1.el8_2",
"firefox-0:128.13.0-1.el9_2",
"firefox-0:128.13.0-1.el9_0",
"firefox-0:128.13.0-1.el8_10",
"thunderbird-0:128.13.0-3.el8_10",
"thunderbird-0:128.13.0-3.el9_2",
"thunderbird-0:128.13.0-3.el8_2",
"thunderbird-0:128.13.0-3.el9_4",
"thunderbird-0:128.13.0-3.el8_4",
"thunderbird-0:128.13.0-3.el9_6",
"thunderbird-0:128.13.0-3.el8_6",
"thunderbird-0:128.13.0-3.el8_8"
],
"bugzilla": "2382718",
"bugzilla_description": "firefox: thunderbird: XSLT documents could bypass CSP",
"cvss3_score": "6.1",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-07-22T20:49:26Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-8032.json",
"severity": "moderate"
} | medium |
| Status status | NVD | Modifiedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Firefox",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.13",
"versionType": "rpm"
},
{
"lessThanOrEqual": "140.*",
"status": "unaffected",
"version": "140.1",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "141",
"versionType": "rpm"
}
]
},
{
"product": "Thunderbird",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.13",
"versionType": "rpm"
},
{
"lessThanOrEqual": "140.*",
"status": "unaffected",
"version": "140.1",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "141",
"versionType": "rpm"
}
]
}
],
"source": "security@mozilla.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "7C22C9BA-7B86-487A-B0A4-419A0D163B56",
"versionEndExcluding": "128.13.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
"matchCriteriaId": "8684A46E-D70A-4830-8971-A6DCC360F422",
"versionEndExcluding": "141.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "BB48C2EF-A6AC-4445-9417-1B65D5BC509B",
"versionEndExcluding": "140.1.0",
"versionStartIncluding": "140.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "B9BB9B0C-2B49-44EA-9BED-241A8CE8794E",
"versionEndExcluding": "128.13.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*",
"matchCriteriaId": "95D506DD-BD9B-4D90-802F-5BE673F1CF14",
"versionEndExcluding": "141.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "8CE266C2-5AF1-4C57-9B7C-47039FF06384",
"versionEndExcluding": "140.1.0",
"versionStartIncluding": "140.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1."
},
{
"lang": "es",
"value": "La carga de documentos XSLT no propagó correctamente el documento fuente, lo que eludió su CSP. Esta vulnerabilidad afecta a Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13 y Thunderbird < 140.1."
}
],
"id": "CVE-2025-8032",
"lastModified": "2026-09-30T18:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.2,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-8032",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-07-23T13:55:17.746727Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-07-22T21:15:50.360",
"references": [
{
"source": "security@mozilla.org",
"tags": [
"Permissions Required"
],
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1974407"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-56/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-58/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-59/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-61/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-62/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-63/"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "https://lists.debian.org/debian-lts-announce/2025/07/msg00016.html"
}
],
"sourceIdentifier": "security@mozilla.org",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-693"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
| Vendor vendor | NVD | Mozillareceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "Firefox",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.13",
"versionType": "rpm"
},
{
"lessThanOrEqual": "140.*",
"status": "unaffected",
"version": "140.1",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "141",
"versionType": "rpm"
}
]
},
{
"product": "Thunderbird",
"vendor": "Mozilla",
"versions": [
{
"lessThanOrEqual": "128.*",
"status": "unaffected",
"version": "128.13",
"versionType": "rpm"
},
{
"lessThanOrEqual": "140.*",
"status": "unaffected",
"version": "140.1",
"versionType": "rpm"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "141",
"versionType": "rpm"
}
]
}
],
"source": "security@mozilla.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "7C22C9BA-7B86-487A-B0A4-419A0D163B56",
"versionEndExcluding": "128.13.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
"matchCriteriaId": "8684A46E-D70A-4830-8971-A6DCC360F422",
"versionEndExcluding": "141.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "BB48C2EF-A6AC-4445-9417-1B65D5BC509B",
"versionEndExcluding": "140.1.0",
"versionStartIncluding": "140.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "B9BB9B0C-2B49-44EA-9BED-241A8CE8794E",
"versionEndExcluding": "128.13.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*",
"matchCriteriaId": "95D506DD-BD9B-4D90-802F-5BE673F1CF14",
"versionEndExcluding": "141.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*",
"matchCriteriaId": "8CE266C2-5AF1-4C57-9B7C-47039FF06384",
"versionEndExcluding": "140.1.0",
"versionStartIncluding": "140.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1."
},
{
"lang": "es",
"value": "La carga de documentos XSLT no propagó correctamente el documento fuente, lo que eludió su CSP. Esta vulnerabilidad afecta a Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13 y Thunderbird < 140.1."
}
],
"id": "CVE-2025-8032",
"lastModified": "2026-09-30T18:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.2,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-8032",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-07-23T13:55:17.746727Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-07-22T21:15:50.360",
"references": [
{
"source": "security@mozilla.org",
"tags": [
"Permissions Required"
],
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1974407"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-56/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-58/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-59/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-61/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-62/"
},
{
"source": "security@mozilla.org",
"tags": [
"Vendor Advisory"
],
"url": "https://www.mozilla.org/security/advisories/mfsa2025-63/"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "https://lists.debian.org/debian-lts-announce/2025/07/msg00016.html"
}
],
"sourceIdentifier": "security@mozilla.org",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-693"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
vulnerability
| firefox: thunderbird: XSLT documents could bypass CSP zetlyn/cve-redhat · 2025-07-22 | cvss 6.1 cwe CWE-693 packages firefox-0:128.13.0-1.el10_0, firefox-0:128.13.0-1.el7_9, firefox-0:128.13.0-1.el8_8, thunderbird-0:128.13.0-3.el9_0, firefox-0:128.13.0-1.el8_6, firefox-0:128.13.0-1.el9_6, thunderbird-0:128.13.0-3.el10_0, firefox-0:128.13.0-1.el8_4, firefox-0:128.13.0-1.el9_4, firefox-0:128.13.0-1.el8_2, firefox-0:128.13.0-1.el9_2, firefox-0:128.13.0-1.el9_0, firefox-0:128.13.0-1.el8_10, thunderbird-0:128.13.0-3.el8_10, thunderbird-0:128.13.0-3.el9_2, thunderbird-0:128.13.0-3.el8_2, thunderbird-0:128.13.0-3.el9_4, thunderbird-0:128.13.0-3.el8_4, thunderbird-0:128.13.0-3.el9_6, thunderbird-0:128.13.0-3.el8_6, thunderbird-0:128.13.0-3.el8_8 severity moderate | source |
| XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1. zetlyn/cve-nvd · 2025-07-22 | cvss 8.1 product Firefox status Modified vendor Mozilla | source |