Количество 9
Количество 9
GHSA-4qpp-gxm3-h9vw
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.
CVE-2025-14523
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.
CVE-2025-14523
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.
CVE-2025-14523
Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)
CVE-2025-14523
A flaw in libsoup\u2019s HTTP header handling allows multiple Host: he ...
SUSE-SU-2026:0123-1
Security update for libsoup
ELSA-2026-0423
ELSA-2026-0423: libsoup3 security update (IMPORTANT)
ELSA-2026-0422
ELSA-2026-0422: libsoup security update (IMPORTANT)
ELSA-2026-0421
ELSA-2026-0421: libsoup security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4qpp-gxm3-h9vw A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers. | CVSS3: 8.2 | 0% Низкий | 2 месяца назад | |
CVE-2025-14523 A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers. | CVSS3: 8.2 | 0% Низкий | 2 месяца назад | |
CVE-2025-14523 A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers. | CVSS3: 8.2 | 0% Низкий | 2 месяца назад | |
CVE-2025-14523 Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins) | 0% Низкий | около 2 месяцев назад | ||
CVE-2025-14523 A flaw in libsoup\u2019s HTTP header handling allows multiple Host: he ... | CVSS3: 8.2 | 0% Низкий | 2 месяца назад | |
SUSE-SU-2026:0123-1 Security update for libsoup | 0% Низкий | 27 дней назад | ||
ELSA-2026-0423 ELSA-2026-0423: libsoup3 security update (IMPORTANT) | 30 дней назад | |||
ELSA-2026-0422 ELSA-2026-0422: libsoup security update (IMPORTANT) | 30 дней назад | |||
ELSA-2026-0421 ELSA-2026-0421: libsoup security update (IMPORTANT) | 30 дней назад |
Уязвимостей на страницу