Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:13978

Опубликовано: 07 мая 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: libsoup security update

The libsoup packages provide an HTTP client and server library for GNOME.

Security Fix(es):

  • libsoup: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment (CVE-2026-5119)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
libsoupi68612.el9_7.6libsoup-2.72.0-12.el9_7.6.i686.rpm
libsoupx86_6412.el9_7.6libsoup-2.72.0-12.el9_7.6.x86_64.rpm
libsoup-develi68612.el9_7.6libsoup-devel-2.72.0-12.el9_7.6.i686.rpm
libsoup-develx86_6412.el9_7.6libsoup-devel-2.72.0-12.el9_7.6.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 5.9
ubuntu
4 месяца назад

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.

CVSS3: 5.9
redhat
4 месяца назад

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.

CVSS3: 5.9
nvd
4 месяца назад

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.

msrc
4 месяца назад

Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment

CVSS3: 5.9
debian
4 месяца назад

A flaw was found in libsoup. When establishing HTTPS tunnels through a ...