VDB
DEBIAN-CVE-2025-14523
DEBIAN-CVE-2025-14523
PUBLISHED
CVSS 8.199999809265137 HIGH
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | libsoup2.4 | 0, 2.74.3-10, 2.74.3-9 |
| Debian:12 | libsoup3 | 0, 3.2.2-2, 3.2.3-0 |
| Debian:13 | libsoup2.4 | 2.74.3-10.1, 0, 2.74.3-11 |
| Debian:13 | libsoup3 | 3.6.5-5, 0, 3.6.5-3 |
| Debian:14 | libsoup3 | 0, 3.6.5-4, 3.6.5-5 |
| Debian:11 | libsoup2.4 | 2.72.0-2, 2.72.0-2, 0 |
Timeline
- Dec 11, 2025 CVE Published
- Apr 28, 2026 CVE Updated