CVE-2025-11712: An OBJECT tag type attribute overrode browser behavior on web resources without a content-type
A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 144 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 144 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.4 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 144 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.4
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11712?
CVE-2025-11712 is considered a medium severity vulnerability due to its potential to facilitate Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-11712?
To fix CVE-2025-11712, users should update their Mozilla Thunderbird or Firefox browsers to the latest version as specified in the security advisories.
What versions are affected by CVE-2025-11712?
CVE-2025-11712 affects Mozilla Thunderbird versions up to 140.4 and Mozilla Firefox versions up to 144.
What can exploit CVE-2025-11712?
CVE-2025-11712 can be exploited by a malicious web page that uses the OBJECT tag to bypass default browser behavior on resources without a content-type header.
What impact does CVE-2025-11712 have on users?
The impact of CVE-2025-11712 on users includes the risk of executing malicious scripts that can lead to data theft or unauthorized actions on affected websites.