CVE-2025-3522
published 2025-04-15CVE-2025-3522: Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird…
PriorityP430medium6.3CVSS 3.1
AVNACLPRNUIRSUCLILAL
EPSS
0.26%
17.5th percentile
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:128.10.0esr-1~deb12u1 (bookworm) | thunderbird 1:128.10.0esr-1~deb12u1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 128.9.2 | 128.9.2 |
| mozilla | thunderbird | >= 0 < 1:128.10.1esr-1~deb11u1 | 1:128.10.1esr-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:128.10.0esr-1~deb12u1 | 1:128.10.0esr-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:128.10.0esr-1 | 1:128.10.0esr-1 |
| mozilla | thunderbird | >= 0 < 1:128.10.0esr-1 | 1:128.10.0esr-1 |
| mozilla | thunderbird | >= 129.0 < 137.0.2 | 137.0.2 |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2025-07-22
CVE-2025-4083 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart thunderbird to
make all the necessary changes.
Red Hat
thunderbird: Leak of hashed Window credentials via crafted attachment URL
vendor_redhat·2025-04-15·CVSS 6.3
CVE-2025-3522 [MEDIUM] CWE-1220 thunderbird: Leak of hashed Window credentials via crafted attachment URL
thunderbird: Leak of hashed Window credentials via crafted attachment URL
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
A flaw was found in Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Thunderbird processes the X-Mozilla-Ex
Debian
CVE-2025-3522: thunderbird - Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle att...
vendor_debian·2025·CVSS 6.3
CVE-2025-3522 [MEDIUM] CVE-2025-3522: thunderbird - Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle att...
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
Scope: local
bookworm: resolved (fixed in 1:128.10.0esr-1~deb12u1)
bullseye: resolved (fixed in 1:128.10.1esr-1~deb11u1)
forky: resolved (fixed in 1:128.10.0esr-1)
sid: resolved (fixed in 1:128.10.0esr-1)
trixie: resolved
Mozilla
Mozilla Foundation Security Advisory 2025-26: CVE-2025-3522
vendor_mozilla·CVSS 6.3
CVE-2025-3522 [MEDIUM] Mozilla Foundation Security Advisory 2025-26: CVE-2025-3522
Mozilla Foundation Security Advisory 2025-26
CVE: CVE-2025-3522
Product: Thunderbird
Impact: low
Fixed in: Thunderbird 137.0.2
Mozilla
Mozilla Foundation Security Advisory 2025-27: CVE-2025-3522
vendor_mozilla·CVSS 6.3
CVE-2025-3522 [MEDIUM] Mozilla Foundation Security Advisory 2025-27: CVE-2025-3522
Mozilla Foundation Security Advisory 2025-27
CVE: CVE-2025-3522
Product: Thunderbird
Impact: low
Fixed in: Thunderbird 128.9.2
GHSA
GHSA-78fw-w53r-pgwg: Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally
ghsa_unreviewed·2025-04-15
CVE-2025-3522 [MEDIUM] CWE-601 GHSA-78fw-w53r-pgwg: Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
OSV
CVE-2025-3522: Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally
osv·2025-04-15·CVSS 6.3
CVE-2025-3522 [MEDIUM] CVE-2025-3522: Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-15
Published