CVE-2025-4086

Source
https://cve.org/CVERecord?id=CVE-2025-4086
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4086.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-4086
Downstream
Related
Published
2025-04-29T14:15:35.267Z
Modified
2026-04-10T05:26:26.189113Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected. This vulnerability affects Firefox < 138 and Thunderbird < 138.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4086.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "138.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "138.0"
            }
        ]
    }
]