CVE-2025-4088
published 2025-04-29CVE-2025-4088: A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had…
PriorityP335medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.15%
4.9th percentile
A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 138.0-1 (sid) | firefox 138.0-1 (sid) |
| mozilla | firefox | < 138.0 | 138.0 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 138.0 | 138.0 |
| mozilla | thunderbird | >= 0 < 1:140.7.1+build1-0ubuntu0.22.04.1 | 1:140.7.1+build1-0ubuntu0.22.04.1 |
| nodejs | undici | >= 0 < 5.29.0 | 5.29.0 |
| nodejs | undici | >= 6.0.0 < 6.21.2 | 6.21.2 |
| nodejs | undici | >= 7.0.0 < 7.5.0 | 7.5.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
undici Denial of Service attack via bad certificate data
ghsa·2025-05-15
CVE-2025-47279 [LOW] CWE-401 undici Denial of Service attack via bad certificate data
undici Denial of Service attack via bad certificate data
### Impact
Applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak.
### Patches
This has been patched in https://github.com/nodejs/undici/pull/4088.
### Workarounds
If a webhook fails, avoid keep calling it repeatedly.
### References
Reported as: https://github.com/nodejs/undici/issues/3895
GHSA
GHSA-vvxh-6r52-hj35: A security vulnerability in Firefox allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had
ghsa_unreviewed·2025-04-29
CVE-2025-4088 [MEDIUM] CWE-352 GHSA-vvxh-6r52-hj35: A security vulnerability in Firefox allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had
A security vulnerability in Firefox allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability affects Firefox < 138 and Thunderbird < 138.
OSV
CVE-2025-4088: A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that
osv·2025-04-29·CVSS 6.5
CVE-2025-4088 [MEDIUM] CVE-2025-4088: A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that
A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability affects Firefox < 138 and Thunderbird < 138.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2026-02-02
CVE-2025-8031 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
firefox: thunderbird: Cross-site request forgery via storage access API redirects
vendor_redhat·2025-04-29·CVSS 6.5
CVE-2025-4088 [MEDIUM] CWE-601 firefox: thunderbird: Cross-site request forgery via storage access API redirects
firefox: thunderbird: Cross-site request forgery via storage access API redirects
A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability affects Firefox < 138 and Thunderbird < 138.
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: A security vulnerability in Firefox allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins.
Statement: Red Hat Product Sec
Debian
CVE-2025-4088: firefox - A security vulnerability in Thunderbird allowed malicious sites to use redirects...
vendor_debian·2025·CVSS 6.5
CVE-2025-4088 [MEDIUM] CVE-2025-4088: firefox - A security vulnerability in Thunderbird allowed malicious sites to use redirects...
A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability affects Firefox < 138 and Thunderbird < 138.
Scope: local
sid: resolved (fixed in 138.0-1)
Mozilla
Mozilla Foundation Security Advisory 2025-31: CVE-2025-4088
vendor_mozilla·CVSS 6.5
CVE-2025-4088 [MEDIUM] Mozilla Foundation Security Advisory 2025-31: CVE-2025-4088
Mozilla Foundation Security Advisory 2025-31
CVE: CVE-2025-4088
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 138
Mozilla
Mozilla Foundation Security Advisory 2025-28: CVE-2025-4088
vendor_mozilla·CVSS 6.5
CVE-2025-4088 [MEDIUM] Mozilla Foundation Security Advisory 2025-28: CVE-2025-4088
Mozilla Foundation Security Advisory 2025-28
CVE: CVE-2025-4088
Product: Firefox
Impact: high
Fixed in: Firefox 138
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-29
Published