Mozilla Firefox and Thunderbird Incorrect URL Stripping in CSP Reports Vulnerability

Vulnerability

A vulnerability exists in Mozilla Firefox and Thunderbird due to improper handling of URLs in Content Security Policy (CSP) reports. Specifically, the 'username:password' portion of URLs was not adequately removed, potentially leading to the unintentional disclosure of HTTP Basic Authentication credentials. This issue affects multiple versions of Firefox and Thunderbird, including Firefox prior to 141, Firefox ESR prior to 128.13 and 140.1, as well as Thunderbird prior to 141, 128.13 and 140.1.

Impact

Exploitation of this vulnerability could result in the leakage of HTTP Basic Authentication credentials.

Remediation

Users can upgrade to Firefox 141, Firefox ESR 128.13 or 140.1, Thunderbird 141, or Thunderbird ESR 128.13 or 140.1 to address this vulnerability.

Added: Jul 22, 2025, 9:44 PM
Updated: Jul 22, 2025, 9:44 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.7
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.