CVE-2025-0239
Executive Summary
CVE-2025-0239 exposes a flaw in Firefox and Thunderbird where Alt-Svc with ALPN fails to validate certificates when a server redirects to an insecure site. This can allow attackers to redirect traffic to a malicious endpoint, bypassing certificate checks and enabling man‑in‑the‑middle attacks. The issue is fixed in Firefox 134/ESR 128.6 and Thunderbird 134/128.6. It is not currently listed in the CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 4.0 (MEDIUM) - Published: 2025-01-07T16:15:38.563 - Last Modified: 2026-10-05T15:10:00.590
Original Description: When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
"Using the power of decision gives you the capacity to get past any excuse to change any and every part of your life in an instant."
— Tony Robbins