CVE-2025-5271: Devtools' preview ignored CSP headers
Published May 27, 2025
·Updated
Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks.
Affected Software
4 affected componentsFixes available
Mozilla Firefox<139
Mozilla Thunderbird<139
139
Mozilla Firefox<139
139
Mozilla Firefox<139.0
Event History
May 27, 2025
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-5271?
The severity of CVE-2025-5271 is considered critical due to the potential for content injection attacks.
2
How do I fix CVE-2025-5271?
To fix CVE-2025-5271, update your Firefox browser to version 139 or later.
3
Who is affected by CVE-2025-5271?
CVE-2025-5271 affects all versions of Firefox prior to version 139.
4
What impact does CVE-2025-5271 have?
CVE-2025-5271 could allow attackers to inject malicious content during response previews in Devtools.
5
What does CSP stand for in the context of CVE-2025-5271?
In the context of CVE-2025-5271, CSP stands for Content Security Policy, which is bypassed during response previews.