{"api_version":"1","generated_at":"2026-07-23T10:56:28+00:00","cve":"CVE-2025-8028","urls":{"html":"https://cve.report/CVE-2025-8028","api":"https://cve.report/api/cve/CVE-2025-8028.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-8028","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-8028"},"summary":{"title":"Large branch table could lead to truncated instruction","description":"On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.","state":"PUBLISHED","assigner":"mozilla","published_at":"2025-07-22 21:15:49","updated_at":"2026-04-13 15:17:08"},"problem_types":["CWE-1332","CWE-1332 CWE-1332 Improper Handling of Faults that Lead to Instruction Skips"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}}],"references":[{"url":"https://www.mozilla.org/security/advisories/mfsa2025-59/","name":"https://www.mozilla.org/security/advisories/mfsa2025-59/","refsource":"security@mozilla.org","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-58/","name":"https://www.mozilla.org/security/advisories/mfsa2025-58/","refsource":"security@mozilla.org","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-56/","name":"https://www.mozilla.org/security/advisories/mfsa2025-56/","refsource":"security@mozilla.org","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-57/","name":"https://www.mozilla.org/security/advisories/mfsa2025-57/","refsource":"security@mozilla.org","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1971581","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1971581","refsource":"security@mozilla.org","tags":["Permissions Required"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-62/","name":"https://www.mozilla.org/security/advisories/mfsa2025-62/","refsource":"security@mozilla.org","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-63/","name":"https://www.mozilla.org/security/advisories/mfsa2025-63/","refsource":"security@mozilla.org","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-61/","name":"https://www.mozilla.org/security/advisories/mfsa2025-61/","refsource":"security@mozilla.org","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://lists.debian.org/debian-lts-announce/2025/07/msg00016.html","name":"https://lists.debian.org/debian-lts-announce/2025/07/msg00016.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-8028","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-8028","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Mozilla","product":"Firefox","version":"unaffected 115.26 115.* rpm","platforms":[]},{"source":"CNA","vendor":"Mozilla","product":"Firefox","version":"unaffected 128.13 128.* rpm","platforms":[]},{"source":"CNA","vendor":"Mozilla","product":"Firefox","version":"unaffected 140.1 140.* rpm","platforms":[]},{"source":"CNA","vendor":"Mozilla","product":"Firefox","version":"unaffected 141 * rpm","platforms":[]},{"source":"CNA","vendor":"Mozilla","product":"Thunderbird","version":"unaffected 128.13 128.* rpm","platforms":[]},{"source":"CNA","vendor":"Mozilla","product":"Thunderbird","version":"unaffected 140.1 140.* rpm","platforms":[]},{"source":"CNA","vendor":"Mozilla","product":"Thunderbird","version":"unaffected 141 * rpm","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Gary Kwong","lang":"en"}],"nvd_cpes":[{"cve_year":"2025","cve_id":"8028","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"-","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"8028","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"esr","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2025-8028","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2025-07-23T14:32:07.056857Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-1332","description":"CWE-1332 Improper Handling of Faults that Lead to Instruction Skips","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-11-04T15:58:24.124Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2025-11-03T20:07:45.506Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"https://lists.debian.org/debian-lts-announce/2025/07/msg00016.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Firefox","vendor":"Mozilla","versions":[{"lessThanOrEqual":"115.*","status":"unaffected","version":"115.26","versionType":"rpm"},{"lessThanOrEqual":"128.*","status":"unaffected","version":"128.13","versionType":"rpm"},{"lessThanOrEqual":"140.*","status":"unaffected","version":"140.1","versionType":"rpm"},{"lessThanOrEqual":"*","status":"unaffected","version":"141","versionType":"rpm"}]},{"product":"Thunderbird","vendor":"Mozilla","versions":[{"lessThanOrEqual":"128.*","status":"unaffected","version":"128.13","versionType":"rpm"},{"lessThanOrEqual":"140.*","status":"unaffected","version":"140.1","versionType":"rpm"},{"lessThanOrEqual":"*","status":"unaffected","version":"141","versionType":"rpm"}]}],"credits":[{"lang":"en","value":"Gary Kwong"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"On arm64, a WASM <code>br_table</code> instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1."}],"value":"On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1."}],"providerMetadata":{"dateUpdated":"2026-04-13T14:26:48.394Z","orgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","shortName":"mozilla"},"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1971581"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-56/"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-57/"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-58/"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-59/"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-61/"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-62/"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-63/"}],"title":"Large branch table could lead to truncated instruction"}},"cveMetadata":{"assignerOrgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","assignerShortName":"mozilla","cveId":"CVE-2025-8028","datePublished":"2025-07-22T20:49:24.592Z","dateReserved":"2025-07-22T10:13:49.236Z","dateUpdated":"2026-04-13T14:26:48.394Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-07-22 21:15:49","lastModifiedDate":"2026-04-13 15:17:08","problem_types":["CWE-1332","CWE-1332 CWE-1332 Improper Handling of Faults that Lead to Instruction Skips"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*","versionEndExcluding":"115.26.0","matchCriteriaId":"D697EDEE-5DF4-4FC2-8128-BC9DC23EFFF3"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*","versionEndExcluding":"141.0","matchCriteriaId":"8684A46E-D70A-4830-8971-A6DCC360F422"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*","versionStartIncluding":"128.0","versionEndExcluding":"128.13.0","matchCriteriaId":"A621920F-5B71-403D-B8F9-EC22F249CD4C"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*","versionStartIncluding":"140.0","versionEndExcluding":"140.1.0","matchCriteriaId":"BB48C2EF-A6AC-4445-9417-1B65D5BC509B"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*","versionEndExcluding":"128.13.0","matchCriteriaId":"B9BB9B0C-2B49-44EA-9BED-241A8CE8794E"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*","versionEndExcluding":"141.0","matchCriteriaId":"95D506DD-BD9B-4D90-802F-5BE673F1CF14"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*","versionStartIncluding":"140.0","versionEndExcluding":"140.1.0","matchCriteriaId":"8CE266C2-5AF1-4C57-9B7C-47039FF06384"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"8028","Ordinal":"1","Title":"Large branch table could lead to truncated instruction","CVE":"CVE-2025-8028","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"8028","Ordinal":"1","NoteData":"On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.","Type":"Description","Title":"Large branch table could lead to truncated instruction"}]}}}