Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:0422

Опубликовано: 15 янв. 2026
Источник: rocky
Оценка: Important

Описание

Important: libsoup security update

The libsoup packages provide an HTTP client and server library for GNOME.

Security Fix(es):

  • libsoup: libsoup: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (First- vs Last-Value Wins) (CVE-2025-14523)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
libsoupi68612.el9_7.3libsoup-2.72.0-12.el9_7.3.i686.rpm
libsoupx86_6412.el9_7.3libsoup-2.72.0-12.el9_7.3.x86_64.rpm
libsoup-develi68612.el9_7.3libsoup-devel-2.72.0-12.el9_7.3.i686.rpm
libsoup-develx86_6412.el9_7.3libsoup-devel-2.72.0-12.el9_7.3.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.2
ubuntu
около 2 месяцев назад

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
nvd
около 2 месяцев назад

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

msrc
около 2 месяцев назад

Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)

CVSS3: 8.2
debian
около 2 месяцев назад

A flaw in libsoup\u2019s HTTP header handling allows multiple Host: he ...

suse-cvrf
25 дней назад

Security update for libsoup