Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-12547

Опубликовано: 21 июл. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 3.4

Описание

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

РелизСтатусПримечание
devel

needs-triage

esm-apps/resolute

needs-triage

esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

needs-triage

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/jammy

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

needs-triage

upstream

needs-triage

Показывать по

EPSS

Процентиль: 14%
0.00228
Низкий

3.4 Low

CVSS3

Связанные уязвимости

CVSS3: 3.4
redhat
4 месяца назад

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

CVSS3: 3.4
nvd
23 дня назад

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

msrc
17 дней назад

Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch

CVSS3: 3.4
debian
23 дня назад

SoupAuthManager caches proxy authentication credentials without scopin ...

CVSS3: 3.4
github
23 дня назад

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

EPSS

Процентиль: 14%
0.00228
Низкий

3.4 Low

CVSS3