No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19088 | If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140 and Thunderbird < 140. |
Ubuntu USN |
USN-7991-1 | Thunderbird vulnerabilities |
Mon, 13 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140 and Thunderbird < 140. | If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability was fixed in Firefox 140 and Thunderbird 140. |
Thu, 30 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | firefox: WebAuthn would allow a user to sign a challenge on a webpage with an invalid TLS certificate | WebAuthn would allow a user to sign a challenge on a webpage with an invalid TLS certificate |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140. | If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140 and Thunderbird < 140. |
| References |
|
Thu, 03 Jul 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla firefox |
|
| CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | |
| Vendors & Products |
Mozilla
Mozilla firefox |
Thu, 26 Jun 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | firefox: WebAuthn would allow a user to sign a challenge on a webpage with an invalid TLS certificate | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 25 Jun 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-295 | |
| Metrics |
cvssV3_1
|
Tue, 24 Jun 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140. | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-04-13T14:31:09.599Z
Reserved: 2025-06-20T14:51:39.059Z
Link: CVE-2025-6433
Updated: 2025-06-25T12:32:33.301Z
Status : Modified
Published: 2025-06-24T13:15:24.327
Modified: 2026-04-13T15:17:07.807
Link: CVE-2025-6433
OpenCVE Enrichment
Updated: 2025-07-06T22:16:29Z
EUVD
Ubuntu USN