---
id: CVE-2025-8039
title: >-
  In some cases search terms persisted in the URL bar even after navigating away
  from the search page
summary: >-
  In some cases search terms persisted in the URL bar even after navigating away
  from the search page. This vulnerability was fixed in Firefox 141, Firefox ESR
  140.1, Thunderbird 141, and Thunderbird 140.1.
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-200
vendor: mozilla
product: firefox
affected:
  - firefox < 140.1
  - firefox < 141.0
  - thunderbird < 140.1
  - thunderbird < 141.0
patched:
  - firefox 141.0
  - thunderbird 141.0
published: '2025-07-22'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8039'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1970997'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-56/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-59/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-61/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-63/'
    label: security@mozilla.org
tags:
  - nvd
epss: 0.00299
epssPercentile: 0.20349
ingestedAt: '2026-09-30T18:17:24.451Z'
---

## Overview

In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.

## Affected

- `firefox < 140.1`
- `firefox < 141.0`
- `thunderbird < 140.1`
- `thunderbird < 141.0`

## Remediation

Upgrade past the affected range:

- `firefox 141.0`
- `thunderbird 141.0`
