Skip to main content

CVE-2025-8037: Nameless cookies shadow secure cookies in Mozilla Firefox

Unknown
VulnerabilityCVE-2025-8037cvecve-2025-8037
Published: Tue Jul 22 2025 (07/22/2025, 20:49:25 UTC)
Source: CVE Database V5
Vendor/Project: Mozilla
Product: Firefox

Description

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

Technical Details

Data Version
5.1
Assigner Short Name
mozilla
Date Reserved
2025-07-22T10:14:04.585Z
Cvss Version
null
State
PUBLISHED

Threat ID: 687ffd51a915ff00f7fb59b8

Added to database: 7/22/2025, 9:06:25 PM

Last updated: 7/22/2025, 9:06:25 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats