Description
When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.
Problem types
Alt-Svc ALPN validation failure when redirected
Product status
Credits
Paul Gerste
References
lists.debian.org/debian-lts-announce/2025/01/msg00004.html
bugzilla.mozilla.org/show_bug.cgi?id=1929156
www.mozilla.org/security/advisories/mfsa2025-01/
www.mozilla.org/security/advisories/mfsa2025-02/
www.mozilla.org/security/advisories/mfsa2025-04/
www.mozilla.org/security/advisories/mfsa2025-05/