Security Advisory

CVE-2025-5266

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-05-27 12:29:25
Last updated 2026-04-13 14:29:08
Assigner mozilla
State PUBLISHED

Description

Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.