← CVE Tracker
9.1CRITICAL
CVE-2025-8037 — Setting a nameless cookie with an equals sign in the value shadowed other cookies.
Mozilla · Firefox · Published 22 Jul 2025 · Modified 30 Sept 2026
Mozilla · Firefox · Published 22 Jul 2025 · Modified 30 Sept 2026
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
Link: adminadda.com/cve/CVE-2025-8037