---
id: CVE-2025-8031
title: >-
  The `username:password` part was not correctly stripped from URLs in CSP
  reports potentially leaking HTTP Basic Authentication credentials
summary: >-
  The `username:password` part was not correctly stripped from URLs in CSP
  reports potentially leaking HTTP Basic Authentication credentials. This
  vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1,
  Thunderbird 1…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-276
vendor: mozilla
product: firefox
affected:
  - firefox < 128.13.0
  - firefox < 141.0
  - 'firefox >= 140.0, < 140.1.0'
  - thunderbird < 128.13.0
  - thunderbird < 141.0
  - 'thunderbird >= 140.0, < 140.1.0'
patched:
  - firefox 140.1.0
  - thunderbird 140.1.0
published: '2025-07-22'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8031'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1971719'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-56/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-58/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-59/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-61/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-62/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-63/'
    label: security@mozilla.org
  - url: 'https://lists.debian.org/debian-lts-announce/2025/07/msg00016.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00465
epssPercentile: 0.379
ingestedAt: '2026-09-30T18:17:24.448Z'
---

## Overview

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.

## Affected

- `firefox < 128.13.0`
- `firefox < 141.0`
- `firefox >= 140.0, < 140.1.0`
- `thunderbird < 128.13.0`
- `thunderbird < 141.0`
- `thunderbird >= 140.0, < 140.1.0`

## Remediation

Upgrade past the affected range:

- `firefox 140.1.0`
- `thunderbird 140.1.0`
