Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NMozilla Firefox
APPMozilla< 140.1.0< 141.0Mozilla Thunderbird
APPMozilla< 140.1.0< 141.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2024-9680CRITICAL9.8⚠ KEVPL ✓same product
Use-after-free w Animation timelines Firefox/Thunderbird — RCE
CVE-2022-26486CRITICAL9.6⚠ KEVPL ✓same product
Use-after-free w WebGPU IPC framework Mozilla — sandbox escape
CVE-2019-11708CRITICAL10.0⚠ KEVPL ✓same product
Mozilla Firefox/Thunderbird: przełamanie sandbox przez IPC Prompt:Open
CVE-2010-3765CRITICAL9.8⚠ KEVPL ✓same product
RCE w Mozilla Firefox przez błąd nsCSSFrameConstructor::ContentAppended
CVE-2026-84119CRITICAL9.6same product
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox...