CVE-2025-5271: Mozilla Firefox

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability was fixed in Firefox 139 and Thunderbird 139.

Affected products

  • Mozilla Firefox: before 139.0 (fixed in 139.0)

Published 2025-05-27. Last modified 2026-09-30.