CVE-2025-8031: Incorrect URL stripping in CSP reports
The username:password part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.
Other sources
The username:password part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
— MITRE
The username:password part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 128.13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 141 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 141 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 128.13 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 141 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 128.13 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-8031?
CVE-2025-8031 has been classified as a moderate severity vulnerability due to potential leakage of HTTP Basic Authentication credentials.
How do I fix CVE-2025-8031?
To address CVE-2025-8031, update Mozilla Firefox to version 141 or later, or Firefox ESR to version 128.13 or later.
What does CVE-2025-8031 affect?
CVE-2025-8031 affects versions of Mozilla Firefox prior to 141 and Firefox ESR versions prior to 128.13.
Who is impacted by CVE-2025-8031?
Users of Mozilla Firefox and Firefox ESR versions that are below the safe update level may be impacted by CVE-2025-8031.
What kind of data is at risk due to CVE-2025-8031?
CVE-2025-8031 poses a risk of leaking HTTP Basic Authentication credentials through improperly handled URLs in CSP reports.