A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2025-8031

CVE-2025-8031: Mozilla Firefox Information Disclosure Bug

CVE-2025-8031 is an information disclosure vulnerability in Mozilla Firefox that exposes HTTP Basic Authentication credentials in CSP reports. This article covers technical details, affected versions, and fixes.

Updated: January 22, 2026

CVE-2025-8031 Overview

CVE-2025-8031 is an Information Leakage vulnerability affecting Mozilla Firefox and Thunderbird browsers. The vulnerability stems from improper handling of URLs in Content Security Policy (CSP) reports, where the username:password component was not correctly stripped from URLs before being included in CSP violation reports. This flaw could result in HTTP Basic Authentication credentials being inadvertently leaked to CSP report endpoints.

When a CSP violation occurs, browsers generate reports that include the blocked URL. In vulnerable versions, if a URL contained embedded HTTP Basic Authentication credentials (in the format https://username:password@example.com), these sensitive credentials would be transmitted to the configured CSP report-uri endpoint without proper sanitization.

Critical Impact

Sensitive HTTP Basic Authentication credentials embedded in URLs may be leaked to third-party CSP report collection endpoints, potentially enabling unauthorized access to protected resources.

Affected Products

  • Mozilla Firefox < 141
  • Mozilla Firefox ESR < 128.13
  • Mozilla Firefox ESR < 140.1
  • Mozilla Thunderbird < 141
  • Mozilla Thunderbird ESR < 128.13
  • Mozilla Thunderbird ESR < 140.1

Discovery Timeline

  • July 22, 2025 - CVE-2025-8031 published to NVD
  • November 3, 2025 - Last updated in NVD database

Technical Details for CVE-2025-8031

Vulnerability Analysis

The vulnerability exists in the URL sanitization logic within Mozilla's CSP implementation. When generating CSP violation reports, the browser must sanitize URLs to prevent sensitive information from being transmitted to potentially untrusted report collection endpoints. According to the CSP specification, user credentials embedded in URLs should be stripped before inclusion in reports to protect sensitive authentication data.

In vulnerable versions, the URL parsing and sanitization routine failed to properly identify and remove the username:password portion of URLs following the scheme delimiter (://). This means that when a web page triggers a CSP violation involving a URL with embedded credentials, those credentials would be included verbatim in the JSON payload sent to the CSP report-uri or report-to endpoint.

The vulnerability is classified under CWE-276 (Incorrect Default Permissions), though the primary security concern relates to information disclosure through improper data handling in security-critical browser functionality.

Root Cause

The root cause is an incomplete implementation of URL sanitization in the CSP reporting mechanism. The code responsible for preparing CSP violation reports failed to properly parse and redact authentication credentials from URLs before serializing them into report payloads. This oversight in the URL processing pipeline allowed sensitive credential data to bypass the intended security controls.

Attack Vector

The attack vector for this vulnerability is network-based and requires no privileges or user interaction. An attacker could exploit this vulnerability through the following scenarios:

Scenario 1: Malicious CSP Report Endpoint
An attacker controlling a website could configure their CSP policy to send reports to an attacker-controlled endpoint. If a user visits this site and the page attempts to load resources using URLs containing embedded credentials, those credentials would be leaked to the attacker's report collection server.

Scenario 2: Third-Party Report Collection
Organizations using third-party CSP monitoring services may inadvertently leak credentials if internal applications use URL-embedded authentication for legacy resources that trigger CSP violations.

Exploitation Mechanism:

The vulnerability can be exploited when a web application with CSP reporting enabled references resources using URLs containing embedded credentials. When these requests violate the CSP policy, the browser generates a report containing the unsanitized URL, transmitting credentials to the configured report endpoint.

For detailed technical information, refer to Mozilla Bug Report #1971719 and the associated security advisories.

Detection Methods for CVE-2025-8031

Indicators of Compromise

  • Outbound network traffic containing CSP violation reports with URLs that include username:password@ patterns
  • Unusual authentication failures on systems protected by HTTP Basic Authentication following CSP report transmission
  • Log entries from CSP report endpoints showing credentials in blocked-uri or document-uri fields
  • Network captures showing sensitive credential data in JSON payloads to report-uri destinations

Detection Strategies

  • Monitor network traffic for CSP violation reports containing authentication credentials in URL patterns
  • Implement content inspection on outbound traffic to CSP report endpoints looking for credential patterns
  • Review CSP report logs for URLs containing the @ symbol preceded by potential username:password combinations
  • Deploy browser version auditing to identify vulnerable Firefox and Thunderbird installations across the enterprise

Monitoring Recommendations

  • Enable detailed logging on CSP report collection endpoints to identify potential credential leakage
  • Configure SIEM rules to alert on CSP reports containing URL patterns matching ://[^@]+:[^@]+@
  • Audit all CSP policies in use across web applications to inventory configured report-uri endpoints
  • Monitor for unauthorized access attempts using credentials that may have been leaked through CSP reports

How to Mitigate CVE-2025-8031

Immediate Actions Required

  • Update Mozilla Firefox to version 141 or later, or Firefox ESR to version 128.13 or 140.1
  • Update Mozilla Thunderbird to version 141 or later, or Thunderbird ESR to version 128.13 or 140.1
  • Audit and rotate any HTTP Basic Authentication credentials that may have been embedded in URLs and exposed through CSP reports
  • Review CSP report logs to identify any credentials that may have already been leaked

Patch Information

Mozilla has released security patches addressing this vulnerability across multiple product lines. Organizations should apply the following updates:

  • Firefox: Update to version 141 or later
  • Firefox ESR: Update to version 128.13 or 140.1 or later
  • Thunderbird: Update to version 141 or later
  • Thunderbird ESR: Update to version 128.13 or 140.1 or later

For complete patch details, refer to the official Mozilla Security Advisories:

  • MFSA 2025-56
  • MFSA 2025-58
  • MFSA 2025-59
  • MFSA 2025-61
  • MFSA 2025-62
  • MFSA 2025-63

Debian users should refer to the Debian LTS Announcement for distribution-specific updates.

Workarounds

  • Avoid using URLs with embedded credentials (username:password@) in web applications until browsers are patched
  • Temporarily disable CSP reporting by removing report-uri and report-to directives from CSP policies if credential leakage is a concern
  • Migrate from HTTP Basic Authentication to more secure authentication mechanisms that don't embed credentials in URLs
  • Implement network-level filtering to redact credentials from outbound CSP report traffic as an interim measure
bash
# Verify Firefox version to ensure patched version is installed
firefox --version
# Expected: Mozilla Firefox 141.0 or later

# Verify Thunderbird version
thunderbird --version
# Expected: Mozilla Thunderbird 141.0 or later

# For enterprise environments, use policy templates to enforce minimum versions
# Example: Check browser version in enterprise management systems

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeInformation Disclosure

  • Vendor/TechMozilla Firefox

  • SeverityCRITICAL

  • CVSS Score9.8

  • EPSS Probability0.14%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-276
  • Technical References
  • Mozilla Bug Report #1971719

  • Debian LTS Announcement July 2025
  • Vendor Resources
  • Mozilla Security Advisory MFSA 2025-56

  • Mozilla Security Advisory MFSA 2025-58

  • Mozilla Security Advisory MFSA 2025-59

  • Mozilla Security Advisory MFSA 2025-61

  • Mozilla Security Advisory MFSA 2025-62

  • Mozilla Security Advisory MFSA 2025-63
  • Related CVEs
  • CVE-2026-8967: Mozilla Firefox Information Disclosure

  • CVE-2026-8965: Mozilla Firefox Information Disclosure Flaw

  • CVE-2026-8966: Mozilla Firefox Info Disclosure Flaw

  • CVE-2026-8958: Firefox Information Disclosure Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English