CVE-2025-5270: Mozilla Firefox
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed in Firefox 139 and Thunderbird 139.
Affected products
- Mozilla Firefox: before 139.0 (fixed in 139.0)
Published 2025-05-27. Last modified 2026-09-30.