CVE-2025-5270
published 2025-05-27CVE-2025-5270: In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed in Firefox 139 and Thunderbird 139.
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.24%
15.1th percentile
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed in Firefox 139 and Thunderbird 139.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 139.0-1 (sid) | firefox 139.0-1 (sid) |
| mozilla | firefox | < 139.0 | 139.0 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | >= 0 < 1:140.7.1+build1-0ubuntu0.22.04.1 | 1:140.7.1+build1-0ubuntu0.22.04.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2026-02-02
CVE-2025-8031 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
firefox: SNI was sometimes unencrypted
vendor_redhat·2025-05-27·CVSS 7.5
CVE-2025-5270 [HIGH] CWE-319 firefox: SNI was sometimes unencrypted
firefox: SNI was sometimes unencrypted
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability affects Firefox < 139 and Thunderbird < 139.
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: In certain cases, SNI could be sent unencrypted, even when encrypted DNS is enabled.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Not affected
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux 10) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scope
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: fire
Debian
CVE-2025-5270: firefox - In certain cases, SNI could have been sent unencrypted even when encrypted DNS w...
vendor_debian·2025·CVSS 7.5
CVE-2025-5270 [HIGH] CVE-2025-5270: firefox - In certain cases, SNI could have been sent unencrypted even when encrypted DNS w...
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability affects Firefox < 139 and Thunderbird < 139.
Scope: local
sid: resolved (fixed in 139.0-1)
Mozilla
Mozilla Foundation Security Advisory 2025-42: CVE-2025-5270
vendor_mozilla·CVSS 7.5
CVE-2025-5270 [HIGH] Mozilla Foundation Security Advisory 2025-42: CVE-2025-5270
Mozilla Foundation Security Advisory 2025-42
CVE: CVE-2025-5270
Product: Firefox
Impact: moderate
Fixed in: Firefox 139
Mozilla
Mozilla Foundation Security Advisory 2025-45: CVE-2025-5270
vendor_mozilla·CVSS 7.5
CVE-2025-5270 [HIGH] Mozilla Foundation Security Advisory 2025-45: CVE-2025-5270
Mozilla Foundation Security Advisory 2025-45
CVE: CVE-2025-5270
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 139
OSV
CVE-2025-5270: In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled
osv·2025-05-27·CVSS 7.5
CVE-2025-5270 [HIGH] CVE-2025-5270: In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability affects Firefox < 139 and Thunderbird < 139.
GHSA
GHSA-hf6r-227w-qwf9: In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled
ghsa_unreviewed·2025-05-27
CVE-2025-5270 [HIGH] CWE-319 GHSA-hf6r-227w-qwf9: In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability affects Firefox < 139.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-27
Published