CVE-2025-8037
published 2025-07-22CVE-2025-8037: Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie…
PriorityP344critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.22%
12.1th percentile
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 141.0-1 (sid) | firefox 141.0-1 (sid) |
| mozilla | firefox | < 140.1 | 140.1 |
| mozilla | firefox | < 141.0 | 141.0 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 140.1 | 140.1 |
| mozilla | thunderbird | < 141.0 | 141.0 |
| mozilla | thunderbird | >= 0 < 1:140.7.1+build1-0ubuntu0.22.04.1 | 1:140.7.1+build1-0ubuntu0.22.04.1 |
| msrc | cbl2_tcpdump_4.9.3-3_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_tcpdump_4.9.3-3_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2026-02-02
CVE-2025-8031 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
firefox: thunderbird: Nameless cookies shadow secure cookies
vendor_redhat·2025-07-22·CVSS 9.1
CVE-2025-8037 [CRITICAL] CWE-614 firefox: thunderbird: Nameless cookies shadow secure cookies
firefox: thunderbird: Nameless cookies shadow secure cookies
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox Secure attribute.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Not affected
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux 10) - Not affected
Package: rhel10/thunderbird-flatpak (Red Hat Enterprise Linux 10) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 10) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbi
Debian
CVE-2025-8037: firefox - Setting a nameless cookie with an equals sign in the value shadowed other cookie...
vendor_debian·2025·CVSS 9.1
CVE-2025-8037 [CRITICAL] CVE-2025-8037: firefox - Setting a nameless cookie with an equals sign in the value shadowed other cookie...
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.
Scope: local
sid: resolved (fixed in 141.0-1)
Microsoft
ppp decapsulator can be convinced to allocate a large amount of memory
vendor_msrc·2020-11-10·CVSS 7.5
CVE-2020-8037 [HIGH] CWE-770 ppp decapsulator can be convinced to allocate a large amount of memory
ppp decapsulator can be convinced to allocate a large amount of memory
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Tcpdump: Tcpdump
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Refer
Mozilla
Mozilla Foundation Security Advisory 2025-59: CVE-2025-8037
vendor_mozilla·CVSS 9.1
CVE-2025-8037 [CRITICAL] Mozilla Foundation Security Advisory 2025-59: CVE-2025-8037
Mozilla Foundation Security Advisory 2025-59
CVE: CVE-2025-8037
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.1
Mozilla
Mozilla Foundation Security Advisory 2025-56: CVE-2025-8037
vendor_mozilla·CVSS 9.1
CVE-2025-8037 [CRITICAL] Mozilla Foundation Security Advisory 2025-56: CVE-2025-8037
Mozilla Foundation Security Advisory 2025-56
CVE: CVE-2025-8037
Product: Firefox
Impact: high
Fixed in: Firefox 141
Mozilla
Mozilla Foundation Security Advisory 2025-61: CVE-2025-8037
vendor_mozilla·CVSS 9.1
CVE-2025-8037 [CRITICAL] Mozilla Foundation Security Advisory 2025-61: CVE-2025-8037
Mozilla Foundation Security Advisory 2025-61
CVE: CVE-2025-8037
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 141
Mozilla
Mozilla Foundation Security Advisory 2025-63: CVE-2025-8037
vendor_mozilla·CVSS 9.1
CVE-2025-8037 [CRITICAL] Mozilla Foundation Security Advisory 2025-63: CVE-2025-8037
Mozilla Foundation Security Advisory 2025-63
CVE: CVE-2025-8037
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.1
OSV
CVE-2025-8037: Setting a nameless cookie with an equals sign in the value shadowed other cookies
osv·2025-07-22·CVSS 9.1
CVE-2025-8037 [CRITICAL] CVE-2025-8037: Setting a nameless cookie with an equals sign in the value shadowed other cookies
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.
GHSA
GHSA-fw75-5frq-vxhg: Setting a nameless cookie with an equals sign in the value shadowed other cookies
ghsa_unreviewed·2025-07-22
CVE-2025-8037 [CRITICAL] CWE-614 GHSA-fw75-5frq-vxhg: Setting a nameless cookie with an equals sign in the value shadowed other cookies
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-8037 firefox: thunderbird: Nameless cookies shadow secure cookies
bugzilla·2025-07-22·CVSS 9.1
CVE-2025-8037 [CRITICAL] CVE-2025-8037 firefox: thunderbird: Nameless cookies shadow secure cookies
CVE-2025-8037 firefox: thunderbird: Nameless cookies shadow secure cookies
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.
Bugzilla
CookieStore set: cookies set from subdomains are host-scoped to (only) eTLD+1, even with the __Host- prefix; document.cookie & cookieStore.getAll() differ
bugzilla·2025-03-04
CookieStore set: cookies set from subdomains are host-scoped to (only) eTLD+1, even with the __Host- prefix; document.cookie & cookieStore.getAll() differ
CookieStore set: cookies set from subdomains are host-scoped to (only) eTLD+1, even with the __Host- prefix; document.cookie & cookieStore.getAll() differ
User Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:136.0) Gecko/20100101 Firefox/136.0
Steps to reproduce:
1. Go to https://y.x.response.ee/
2. Open devtools (F12), Console tab
3. Execute the following JavaScript:
```
await cookieStore.set("__Host-x", "y")
```
4. Go to https://response.ee/
5. Open devtools (F12), Storage tab
Actual results:
See that the cookie is automatically set for whole site-scope (response.ee) from y.x.response.ee, even with `__Host-` prefix, not only for the host that set them (y.x.response.ee)
Expected results:
The default should be no Domain attribute, like with `document.cookie` or `Set-Cookie`.
Try
2025-07-22
Published