CVE-2025-8031
9.8
CRITICAL
CVSS 3.1
EPSS 0.44%
Description
The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
How to fix CVE-2025-8031
To remediate CVE-2025-8031, upgrade the affected package to a fixed version below.
- Debian/firefox-esr—upgrade to 128.13.0esr-1~deb11u1 or later
- —upgrade to 1:128.13.0esr-1~deb11u1 or later
Is CVE-2025-8031 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 128.13.0esr-1~deb11u1
- from 0, < 1:128.13.0esr-1~deb11u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |