CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-8031

CVE-2025-8031. CVSS base score 9.8 (CRITICAL, Source advisory). EPSS 0.00465 (percentile 0.38059), scored 2026-10-04.

Affected technology

firefox · before 128.13.0 (exclusive)
mozilla

firefox · before 141.0 (exclusive)
mozilla

firefox · from 140.0 (inclusive), before 140.1.0 (exclusive)
mozilla

thunderbird · before 128.13.0 (exclusive)
mozilla

thunderbird · before 141.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.1.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-276
CCR priority
39.3 /100 (P4)
CVSS
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · Source advisory
EPSS
0.00465 · percentile 0.38059 · 2026-10-04
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-8031.html