Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2025-0239

MEDIUM 4.0

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

Attack vector : Local No privileges required No user interaction
Show raw CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS 0.23% exploit very unlikely percentile 13.4%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (2)
Vendor Product Versions
mozilla thunderbird
All platforms (wildcard)
<128.6.0
mozilla thunderbird
All platforms (wildcard)
≥129.0 <134.0
View on NVD ↗ Advisory · www.mozilla.org