---
id: CVE-2025-0239
title: >-
  When using Alt-Svc, ALPN did not properly validate certificates when the
  original server is redirecting to an insecure site
summary: >-
  When using Alt-Svc, ALPN did not properly validate certificates when the
  original server is redirecting to an insecure site. This vulnerability was
  fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird
  128.6.
severity: medium
cvss: 4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-295
vendor: mozilla
product: firefox
affected:
  - firefox < 128.6.0
  - firefox < 134.0
  - thunderbird < 128.6.0
  - 'thunderbird >= 129.0, < 134.0'
patched:
  - firefox 134.0
  - thunderbird 134.0
published: '2025-01-07'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T19:10:01.007'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-0239'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1929156'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-01/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-02/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-04/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-05/'
    label: security@mozilla.org
  - url: 'https://lists.debian.org/debian-lts-announce/2025/01/msg00004.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00226
epssPercentile: 0.12108
ingestedAt: '2026-09-30T19:21:07.218Z'
---

## Overview

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

## Affected

- `firefox < 128.6.0`
- `firefox < 134.0`
- `thunderbird < 128.6.0`
- `thunderbird >= 129.0, < 134.0`

## Remediation

Upgrade past the affected range:

- `firefox 134.0`
- `thunderbird 134.0`
