alpine · CVE-2025-14331

Quick triage

Priority: not assigned Published: Updated:

View at Official alpine advisory, NVD, CVE.org · CVE detail

Freshness: no update timestamp found; verify against the upstream OS advisory manually.

Tracker summary

CVE-2025-14331: 3 source package rows (firefox, firefox-esr, thunderbird); 416 state rows across 3 repos (3.22-community, 3.23-community, edge-community); fixed 0, open 416.

Description:

Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

cvelogic Threat Intelligence