CVE-2025-0239: Alt-Svc ALPN validation failure when redirected
Last updated 9 January 2025
Other sources
When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0239?
CVE-2025-0239 has been rated as a high severity vulnerability due to its impact on certificate validation during insecure redirects.
How do I fix CVE-2025-0239?
To fix CVE-2025-0239, update your Firefox or Thunderbird application to the latest version available, specifically version 134 or 128.6 for Firefox ESR.
Which versions of Firefox are affected by CVE-2025-0239?
CVE-2025-0239 affects Firefox versions prior to 134 and Firefox ESR versions prior to 128.6.
Is Thunderbird affected by CVE-2025-0239?
Yes, Thunderbird versions prior to 134 and 128.6 are affected by CVE-2025-0239.
What type of vulnerability is CVE-2025-0239?
CVE-2025-0239 is a security vulnerability related to improper certificate validation in Alt-Svc and ALPN.