CVE-2025-5270: SNI was sometimes unencrypted
Published May 27, 2025
·Updated
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled.
Affected Software
4 affected componentsFixes available
Mozilla Firefox<139
Mozilla Thunderbird<139
139
Mozilla Firefox<139
139
Mozilla Firefox<139.0
Event History
May 27, 2025
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-5270?
CVE-2025-5270 has a moderate severity as it could expose SNI information even when encrypted DNS is enabled.
2
How do I fix CVE-2025-5270?
To fix CVE-2025-5270, update your Mozilla Firefox to version 139 or later.
3
Which versions of Firefox are affected by CVE-2025-5270?
CVE-2025-5270 affects all versions of Mozilla Firefox prior to 139.
4
What does SNI mean in the context of CVE-2025-5270?
SNI stands for Server Name Indication, which is an extension of the TLS protocol that allows a client to specify the hostname it is trying to connect to.
5
Can CVE-2025-5270 be exploited remotely?
Yes, CVE-2025-5270 can potentially be exploited remotely, allowing attackers to intercept unencrypted SNI traffic.