Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 22

Количество 22

ubuntu логотип

CVE-2025-14523

8 месяцев назад

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2025-14523

8 месяцев назад

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2025-14523

8 месяцев назад

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2025-14523

7 месяцев назад

Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)

EPSS: Низкий
debian логотип

CVE-2025-14523

8 месяцев назад

A flaw in libsoup\u2019s HTTP header handling allows multiple Host: he ...

CVSS3: 8.2
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0123-1

7 месяцев назад

Security update for libsoup

EPSS: Низкий
rocky логотип

RLSA-2026:0423

7 месяцев назад

Important: libsoup3 security update

EPSS: Низкий
rocky логотип

RLSA-2026:0422

7 месяцев назад

Important: libsoup security update

EPSS: Низкий
rocky логотип

RLSA-2026:0421

7 месяцев назад

Important: libsoup security update

EPSS: Низкий
github логотип

GHSA-4qpp-gxm3-h9vw

8 месяцев назад

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
EPSS: Низкий
oracle-oval логотип

ELSA-2026-0925

6 месяцев назад

ELSA-2026-0925: libsoup security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-0423

7 месяцев назад

ELSA-2026-0423: libsoup3 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-0422

7 месяцев назад

ELSA-2026-0422: libsoup security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-0421

7 месяцев назад

ELSA-2026-0421: libsoup security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2026-03568

8 месяцев назад

Уязвимость библиотеки libsoup, связанная с недостатками обработки http-запросов, позволяющая нарушителю отправить скрытый HTTP-запрос (атака типа HTTP Request Smuggling)

CVSS3: 8.2
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0258-1

6 месяцев назад

Security update for libsoup2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0253-1

6 месяцев назад

Security update for libsoup2

EPSS: Низкий
redos логотип

ROS-20260310-73-0018

5 месяцев назад

Уязвимость libsoup

CVSS3: 8.2
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0257-1

6 месяцев назад

Security update for libsoup

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0211-1

6 месяцев назад

Security update for libsoup

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-14523

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
1%
Низкий
8 месяцев назад
redhat логотип
CVE-2025-14523

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
1%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-14523

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
1%
Низкий
8 месяцев назад
msrc логотип
CVE-2025-14523

Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)

1%
Низкий
7 месяцев назад
debian логотип
CVE-2025-14523

A flaw in libsoup\u2019s HTTP header handling allows multiple Host: he ...

CVSS3: 8.2
1%
Низкий
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0123-1

Security update for libsoup

1%
Низкий
7 месяцев назад
rocky логотип
RLSA-2026:0423

Important: libsoup3 security update

1%
Низкий
7 месяцев назад
rocky логотип
RLSA-2026:0422

Important: libsoup security update

1%
Низкий
7 месяцев назад
rocky логотип
RLSA-2026:0421

Important: libsoup security update

1%
Низкий
7 месяцев назад
github логотип
GHSA-4qpp-gxm3-h9vw

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
1%
Низкий
8 месяцев назад
oracle-oval логотип
ELSA-2026-0925

ELSA-2026-0925: libsoup security update (IMPORTANT)

1%
Низкий
6 месяцев назад
oracle-oval логотип
ELSA-2026-0423

ELSA-2026-0423: libsoup3 security update (IMPORTANT)

1%
Низкий
7 месяцев назад
oracle-oval логотип
ELSA-2026-0422

ELSA-2026-0422: libsoup security update (IMPORTANT)

1%
Низкий
7 месяцев назад
oracle-oval логотип
ELSA-2026-0421

ELSA-2026-0421: libsoup security update (IMPORTANT)

1%
Низкий
7 месяцев назад
fstec логотип
BDU:2026-03568

Уязвимость библиотеки libsoup, связанная с недостатками обработки http-запросов, позволяющая нарушителю отправить скрытый HTTP-запрос (атака типа HTTP Request Smuggling)

CVSS3: 8.2
1%
Низкий
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0258-1

Security update for libsoup2

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0253-1

Security update for libsoup2

6 месяцев назад
redos логотип
ROS-20260310-73-0018

Уязвимость libsoup

CVSS3: 8.2
1%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0257-1

Security update for libsoup

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0211-1

Security update for libsoup

6 месяцев назад

Уязвимостей на страницу