Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-12547

Опубликовано: 21 июл. 2026
Источник: debian
EPSS Низкий

Описание

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsoup3unfixedpackage
libsoup3no-dsatrixiepackage
libsoup2.4removedpackage
libsoup2.4no-dsatrixiepackage

Примечания

  • https://gitlab.gnome.org/GNOME/libsoup/-/work_items/506

EPSS

Процентиль: 14%
0.00228
Низкий

Связанные уязвимости

CVSS3: 3.4
ubuntu
23 дня назад

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

CVSS3: 3.4
redhat
4 месяца назад

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

CVSS3: 3.4
nvd
23 дня назад

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

msrc
17 дней назад

Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch

CVSS3: 3.4
github
23 дня назад

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

EPSS

Процентиль: 14%
0.00228
Низкий