CVE-2018-18506: Medium severity Mozilla Firefox ESR vulnerability
Last updated 25 August 2025
Other sources
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 60.6 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 60.6 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 65 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 152.0.1-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 140.12.0esr-1~deb11u1Fixed in 140.10.2esr-1~deb12u1Fixed in 140.12.0esr-1~deb12u1Fixed in 140.10.2esr-1~deb13u1Fixed in 140.12.0esr-1~deb13u1Fixed in 140.11.0esr-1Fixed in 140.12.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:140.12.0esr-1~deb11u1Fixed in 1:140.10.1esr-1~deb12u1Fixed in 1:140.12.0esr-1~deb12u1Fixed in 1:140.10.1esr-1~deb13u1Fixed in 1:140.12.0esr-1~deb13u1Fixed in 1:140.11.0esr-1Fixed in 1:140.12.0esr-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1~deb11u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.10.2esr-1~deb12u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1~deb12u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.10.2esr-1~deb13u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1~deb13u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.11.0esr-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.12.0esr-1~deb11u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.10.1esr-1~deb12u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.12.0esr-1~deb12u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.10.1esr-1~deb13u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.12.0esr-1~deb13u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.12.0esr-1 - Configuration
Disable proxy auto-detection (WPAD) / 'Auto-detect proxy settings' in the browser Network Settings. Do not load local PAC files that can route localhost requests through a proxy; use manual proxy configuration or no proxy if a proxy is not required.
Firefox / Thunderbird Proxy auto-detection (WPAD) / Auto-detect proxy settings = disabled
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2018-18506?
CVE-2018-18506 has a moderate severity rating, as it affects the handling of Proxy Auto-Configuration (PAC) files.
How do I fix CVE-2018-18506?
To fix CVE-2018-18506, update affected software, such as Firefox and Thunderbird, to versions higher than 60.6.
What software is affected by CVE-2018-18506?
CVE-2018-18506 affects Mozilla Firefox ESR, Mozilla Thunderbird, and versions of Firefox up to 65.
What is the impact of CVE-2018-18506?
CVE-2018-18506 allows a PAC file to route localhost requests through a configured proxy, potentially leading to privacy issues.
When was CVE-2018-18506 announced?
CVE-2018-18506 was publicly announced in July 2024.