---
id: CVE-2025-8036
title: Thunderbird cached CORS preflight responses across IP address changes
summary: >-
  Thunderbird cached CORS preflight responses across IP address changes. This
  allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in
  Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-350
vendor: mozilla
product: firefox
affected:
  - firefox < 140.1.0
  - firefox < 141.0
  - thunderbird < 140.1.0
  - thunderbird < 141.0
patched:
  - firefox 141.0
  - thunderbird 141.0
published: '2025-07-22'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8036'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1960834'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-56/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-59/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-61/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-63/'
    label: security@mozilla.org
  - url: 'https://www.kb.cert.org/vuls/id/652514'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00424
epssPercentile: 0.34343
ingestedAt: '2026-09-30T18:17:24.449Z'
---

## Overview

Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.

## Affected

- `firefox < 140.1.0`
- `firefox < 141.0`
- `thunderbird < 140.1.0`
- `thunderbird < 141.0`

## Remediation

Upgrade past the affected range:

- `firefox 141.0`
- `thunderbird 141.0`
