Introducing Wiz for Exposure Management: Unify, prioritize, and remediate exposures everywhere.

CVE-2025-8204
NixOS vulnerability analysis and mitigation

Overview

A vulnerability classified as problematic was discovered in Comodo Dragon browser versions up to 134.0.6998.179, identified as CVE-2025-8204. The vulnerability affects the HSTS (HTTP Strict Transport Security) Handler component and involves improper implementation of security checks for standard protocols. The issue was initially disclosed on July 25, 2025, and the vendor was contacted but did not respond to the disclosure (VulDB, NVD).

Technical details

The vulnerability stems from an improperly implemented security check in the HSTS Handler component (CWE-358). By default, while normal browsers like Chromium prevent users from connecting to websites with invalid certificates when HSTS is enabled, Comodo Dragon has HSTS disabled. This allows users to proceed to websites with invalid certificates by clicking on the "Proceed to website" option. The vulnerability has received a CVSS v3.1 base score of 3.7 (LOW) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N (NVD, FMISec).

Impact

The vulnerability allows attackers to potentially direct users to spoofed websites despite invalid SSL certificates, which would normally be blocked by HSTS security measures. This creates a risk where users might unknowingly connect to malicious websites, potentially exposing them to phishing attacks and other security threats (FMISec).

Mitigation and workarounds

No official patches or mitigations have been provided by the vendor as they have not responded to the disclosure. It is recommended to consider using alternative browsers that properly implement HSTS security measures (VulDB).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management