Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5119

Опубликовано: 30 мар. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.

Отчет

Moderate impact. This flaw in libsoup allows sensitive session cookies to be transmitted in cleartext within the initial HTTP CONNECT request when establishing HTTPS tunnels through a configured HTTP proxy. A network-positioned attacker or a malicious HTTP proxy could intercept these cookies, potentially leading to session hijacking or user impersonation. This affects Red Hat Enterprise Linux systems configured to use an HTTP proxy for HTTPS connections.

Меры по смягчению последствий

To mitigate this issue, ensure that all HTTP proxies used for HTTPS tunnels are trusted and operate within a secure network. Avoid configuring applications to use untrusted HTTP proxies. If feasible, configure applications to bypass proxies for sensitive connections or utilize a secure proxy solution that encrypts the entire communication channel. A service restart or application reload may be required for changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libsoupOut of support scope
Red Hat Enterprise Linux 10libsoup3FixedRHSA-2026:1596811.05.2026
Red Hat Enterprise Linux 10libsoup3FixedRHSA-2026:1914319.05.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportlibsoup3FixedRHSA-2026:1748214.05.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportlibsoupFixedRHSA-2026:2472209.06.2026
Red Hat Enterprise Linux 8libsoupFixedRHSA-2026:1408706.05.2026
Red Hat Enterprise Linux 8libsoupFixedRHSA-2026:1408706.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportlibsoupFixedRHSA-2026:2271603.06.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnlibsoupFixedRHSA-2026:2271603.06.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportlibsoupFixedRHSA-2026:2434408.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-319
https://bugzilla.redhat.com/show_bug.cgi?id=2452932libsoup: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment

EPSS

Процентиль: 17%
0.00254
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
4 месяца назад

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.

CVSS3: 5.9
nvd
4 месяца назад

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.

msrc
4 месяца назад

Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment

CVSS3: 5.9
debian
4 месяца назад

A flaw was found in libsoup. When establishing HTTPS tunnels through a ...

rocky
2 месяца назад

Moderate: libsoup security update

EPSS

Процентиль: 17%
0.00254
Низкий

5.9 Medium

CVSS3