CVE-2025-14331: Same-origin policy bypass in the Request Handling component
Same-origin policy bypass in the Request Handling component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, and Firefox ESR < 140.6.
Other sources
Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.31 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 146 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 146 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.31 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.6 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 146 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.6
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-14331?
CVE-2025-14331 is classified as a high severity vulnerability due to its potential impact on user privacy and security.
How do I fix CVE-2025-14331?
To fix CVE-2025-14331, users should update Firefox to version 146 or later, or Firefox ESR to version 115.31 or later.
What does CVE-2025-14331 affect?
CVE-2025-14331 affects versions of Firefox prior to 146 and Firefox ESR prior to 115.31 and 140.6.
What is the nature of the vulnerability in CVE-2025-14331?
CVE-2025-14331 is a same-origin policy bypass vulnerability in the Request Handling component.
Who is impacted by CVE-2025-14331?
Individuals using affected versions of Firefox or Firefox ESR are at risk due to CVE-2025-14331.