CVE-2025-3028: Use-after-free triggered by XSLTProcessor
JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 137 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 128.9 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.22 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 128.9 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 137 - Upgrade
Upgrade
Thunderbird ESRto a version that resolves this vulnerability.Fixed in 128.9
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-3028?
CVE-2025-3028 is classified as a high severity vulnerability due to the potential for use-after-free conditions in affected Mozilla products.
How do I fix CVE-2025-3028?
To address CVE-2025-3028, users should update their Firefox or Thunderbird to the latest versions 115.22, 128.9, or 137 as applicable.
Which versions are affected by CVE-2025-3028?
CVE-2025-3028 affects Firefox versions before 137, Firefox ESR versions before 115.22 and 128.9, as well as Thunderbird versions before 137.
What products are impacted by CVE-2025-3028?
CVE-2025-3028 impacts Mozilla Firefox, Firefox ESR, and Thunderbird related products.
Is there a workaround for CVE-2025-3028?
There are no recommended workarounds for CVE-2025-3028; updating to the secure versions is the only effective solution.