CVE-2025-5266: Script element events leaked cross-origin resource status
Published May 27, 2025
·Updated
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks.
Affected Software
8 affected componentsFixes available
Mozilla Firefox<139
Mozilla Firefox ESR<128.11
Mozilla Thunderbird<128.11
128.11
Mozilla Thunderbird<139
139
Mozilla Firefox ESR<128.11
128.11
Mozilla Firefox<139
139
Mozilla Firefox<128.11.0
Mozilla Firefox<139.0
Event History
May 27, 2025
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
Description
Data Sourced
via Red Hat·01:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-5266?
The severity of CVE-2025-5266 is classified as moderate due to its potential to enable XS-Leaks attacks.
2
How do I fix CVE-2025-5266?
To fix CVE-2025-5266, update Mozilla Firefox to version 139 or Firefox ESR to version 128.11.
3
Which versions of Firefox are affected by CVE-2025-5266?
CVE-2025-5266 affects versions of Firefox prior to 139 and Firefox ESR prior to 128.11.
4
What kind of attacks can CVE-2025-5266 enable?
CVE-2025-5266 can enable XS-Leaks attacks by leaking information through load and error events from cross-origin resources.
5
Is user interaction required for CVE-2025-5266 to be exploited?
No, CVE-2025-5266 can be exploited without user interaction, highlighting its significance.