CVE-2025-10536: Information disclosure in the Networking: Cache component
Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
Other sources
This vulnerability affects Firefox < 143 and Firefox ESR < 140.3.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10536?
CVE-2025-10536 is considered a critical vulnerability affecting specific versions of Firefox and Firefox ESR.
How do I fix CVE-2025-10536?
To fix CVE-2025-10536, update Firefox to version 143 or later, or Firefox ESR to version 140.3 or later.
Which versions of Firefox are affected by CVE-2025-10536?
CVE-2025-10536 affects Firefox versions earlier than 143 and Firefox ESR versions earlier than 140.3.
What types of attacks can CVE-2025-10536 enable?
CVE-2025-10536 may enable remote code execution attacks, potentially compromising user systems.
Is there a workaround for CVE-2025-10536?
No official workaround is provided for CVE-2025-10536; updating the software is the recommended approach.