CVE-2025-4086
published 2025-04-29CVE-2025-4086: A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog…
PriorityP433medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.26%
17.5th percentile
A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog.
*This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.*. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 138.0 | 138.0 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 138.0 | 138.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-4086: A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download
osv·2025-04-29·CVSS 6.5
CVE-2025-4086 [MEDIUM] CVE-2025-4086: A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download
A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.
GHSA
GHSA-54jr-pmx4-5pvr: A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download
ghsa_unreviewed·2025-04-29
CVE-2025-4086 [MEDIUM] CWE-451 GHSA-54jr-pmx4-5pvr: A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download
A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog.
*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.
Red Hat
firefox: thunderbird: Specially crafted filename could be used to obscure download type
vendor_redhat·2025-04-29·CVSS 6.5
CVE-2025-4086 [MEDIUM] CWE-451 firefox: thunderbird: Specially crafted filename could be used to obscure download type
firefox: thunderbird: Specially crafted filename could be used to obscure download type
A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog.
*This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. This bug only affects Firefox for Android. Other versions of Firefox are unaffected.
Statement: Red Hat Product Security rates th
Debian
CVE-2025-4086: firefox - A specially crafted filename containing a large number of encoded newline charac...
vendor_debian·2025·CVSS 6.5
CVE-2025-4086 [MEDIUM] CVE-2025-4086: firefox - A specially crafted filename containing a large number of encoded newline charac...
A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2025-31: CVE-2025-4086
vendor_mozilla·CVSS 6.5
CVE-2025-4086 [MEDIUM] Mozilla Foundation Security Advisory 2025-31: CVE-2025-4086
Mozilla Foundation Security Advisory 2025-31
CVE: CVE-2025-4086
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 138
Mozilla
Mozilla Foundation Security Advisory 2025-28: CVE-2025-4086
vendor_mozilla·CVSS 6.5
CVE-2025-4086 [MEDIUM] Mozilla Foundation Security Advisory 2025-28: CVE-2025-4086
Mozilla Foundation Security Advisory 2025-28
CVE: CVE-2025-4086
Product: Firefox
Impact: high
Fixed in: Firefox 138
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-29
Published