Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade thunderbird-esrUpgrade firefox-esrUpgrade firefoxUpgrade thunderbird | Jul 25, 2025 | Jul 24, 2025 |
| Mfsa2025 56 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 141.0 | Jul 23, 2025 | Jul 22, 2025 |
| Mfsa2025 59 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 140.1 | Jul 23, 2025 | Jul 22, 2025 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 140.1 | Jul 23, 2025 | Jul 22, 2025 |
| Suse | — | Upgrade pipewire-langUpgrade xdg-desktop-portal-langUpgrade pipewire-spa-plugins-0_2Upgrade MozillaFirefox-translations-otherUpgrade MozillaThunderbird-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-commonUpgrade pipewire-toolsUpgrade xdg-desktop-portalUpgrade pipewire-spa-toolsUpgrade pipewireUpgrade pipewire-modules-0_3Upgrade MozillaThunderbirdUpgrade xdg-desktop-portal-develUpgrade gstreamer-plugin-pipewireUpgrade pipewire-modulesUpgrade mozillafirefox-branding-upstreamUpgrade libpipewire-0_3-0Upgrade MozillaThunderbird-translations-commonUpgrade mozillafirefox-branding-sleUpgrade MozillaFirefox | Dec 5, 2025 | Jul 25, 2025 |
| Ubuntu | — | Upgrade thunderbird | Jul 24, 2025 | Jul 22, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub