VDB

DEBIAN-CVE-2026-1539

DEBIAN-CVE-2026-1539 PUBLISHED CVSS 5.800000190734863 MEDIUM

A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to third-party servers. Applications using libsoup for HTTP communication may unintentionally expose proxy authentication data.

Risk Scores

CVSS 3.1
5.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Affected Products

VendorProductVersions
Debian:13libsoup2.40, 2.74.3-11, 2.74.3-10.1
Debian:14libsoup30, 3.6.5-5, 3.6.5-7
Debian:13libsoup33.6.5-5, 3.6.5-4, 3.6.5-3
Debian:11libsoup2.42.74.3-8.1, 0, 2.72.0-2+deb11u2
Debian:12libsoup33.4.2-3, 3.4.0-1, 3.4.1-1
Debian:12libsoup2.42.74.3-1, *, *

Timeline

  • Jan 28, 2026 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›