Логотип exploitDog
bind:"GHSA-4qpp-gxm3-h9vw" OR bind:"CVE-2025-14523"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-4qpp-gxm3-h9vw" OR bind:"CVE-2025-14523"

Количество 9

Количество 9

github логотип

GHSA-4qpp-gxm3-h9vw

2 месяца назад

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2025-14523

2 месяца назад

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2025-14523

2 месяца назад

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2025-14523

около 2 месяцев назад

Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)

EPSS: Низкий
debian логотип

CVE-2025-14523

2 месяца назад

A flaw in libsoup\u2019s HTTP header handling allows multiple Host: he ...

CVSS3: 8.2
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0123-1

27 дней назад

Security update for libsoup

EPSS: Низкий
oracle-oval логотип

ELSA-2026-0423

30 дней назад

ELSA-2026-0423: libsoup3 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-0422

30 дней назад

ELSA-2026-0422: libsoup security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-0421

30 дней назад

ELSA-2026-0421: libsoup security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4qpp-gxm3-h9vw

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2025-14523

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-14523

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
0%
Низкий
2 месяца назад
msrc логотип
CVE-2025-14523

Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)

0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-14523

A flaw in libsoup\u2019s HTTP header handling allows multiple Host: he ...

CVSS3: 8.2
0%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0123-1

Security update for libsoup

0%
Низкий
27 дней назад
oracle-oval логотип
ELSA-2026-0423

ELSA-2026-0423: libsoup3 security update (IMPORTANT)

30 дней назад
oracle-oval логотип
ELSA-2026-0422

ELSA-2026-0422: libsoup security update (IMPORTANT)

30 дней назад
oracle-oval логотип
ELSA-2026-0421

ELSA-2026-0421: libsoup security update (IMPORTANT)

30 дней назад

Уязвимостей на страницу