CVE-2025-27426

CWE-601Open Redirect6 documents6 sources
Severity
5.4MEDIUM
EPSS
0.4%
top 41.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 4

Description

Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL This vulnerability affects Firefox for iOS < 136.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages2 packages

NVDmozilla/firefox< 136.0
CVEListV5mozilla/firefox_for_iosunspecified136

🔴Vulnerability Details

3
OSV
CVE-2025-27426: Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL This vulnerability affects Firefox2025-03-04
CVEList
CVE-2025-27426: Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL This vulnerability affects Firefox2025-03-04
GHSA
GHSA-57gw-hcmr-f4g2: Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL This vulnerability affects Firefox2025-03-04

📋Vendor Advisories

2
Debian
CVE-2025-27426: firefox - Malicious websites utilizing a server-side redirect to an internal error page co...2025
Mozilla
Mozilla Foundation Security Advisory 2025-13: CVE-2025-27426
CVE-2025-27426 (MEDIUM CVSS 5.4) | Malicious websites utilizing a serv | cvebase.io