Логотип exploitDog
bind:CVE-2025-14523
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-14523

Количество 17

Количество 17

ubuntu логотип

CVE-2025-14523

около 2 месяцев назад

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2025-14523

около 2 месяцев назад

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2025-14523

около 2 месяцев назад

Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)

EPSS: Низкий
debian логотип

CVE-2025-14523

около 2 месяцев назад

A flaw in libsoup\u2019s HTTP header handling allows multiple Host: he ...

CVSS3: 8.2
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0123-1

26 дней назад

Security update for libsoup

EPSS: Низкий
rocky логотип

RLSA-2026:1509

9 дней назад

Important: spice-client-win security update

EPSS: Низкий
rocky логотип

RLSA-2026:0423

25 дней назад

Important: libsoup3 security update

EPSS: Низкий
rocky логотип

RLSA-2026:0422

25 дней назад

Important: libsoup security update

EPSS: Низкий
rocky логотип

RLSA-2026:0421

26 дней назад

Important: libsoup security update

EPSS: Низкий
github логотип

GHSA-4qpp-gxm3-h9vw

около 2 месяцев назад

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
EPSS: Низкий
oracle-oval логотип

ELSA-2026-0423

28 дней назад

ELSA-2026-0423: libsoup3 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-0422

28 дней назад

ELSA-2026-0422: libsoup security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-0421

28 дней назад

ELSA-2026-0421: libsoup security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0258-1

17 дней назад

Security update for libsoup2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0253-1

17 дней назад

Security update for libsoup2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0257-1

17 дней назад

Security update for libsoup

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0211-1

18 дней назад

Security update for libsoup

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-14523

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-14523

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
0%
Низкий
около 2 месяцев назад
msrc логотип
CVE-2025-14523

Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)

0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-14523

A flaw in libsoup\u2019s HTTP header handling allows multiple Host: he ...

CVSS3: 8.2
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0123-1

Security update for libsoup

0%
Низкий
26 дней назад
rocky логотип
RLSA-2026:1509

Important: spice-client-win security update

0%
Низкий
9 дней назад
rocky логотип
RLSA-2026:0423

Important: libsoup3 security update

0%
Низкий
25 дней назад
rocky логотип
RLSA-2026:0422

Important: libsoup security update

0%
Низкий
25 дней назад
rocky логотип
RLSA-2026:0421

Important: libsoup security update

0%
Низкий
26 дней назад
github логотип
GHSA-4qpp-gxm3-h9vw

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS3: 8.2
0%
Низкий
около 2 месяцев назад
oracle-oval логотип
ELSA-2026-0423

ELSA-2026-0423: libsoup3 security update (IMPORTANT)

28 дней назад
oracle-oval логотип
ELSA-2026-0422

ELSA-2026-0422: libsoup security update (IMPORTANT)

28 дней назад
oracle-oval логотип
ELSA-2026-0421

ELSA-2026-0421: libsoup security update (IMPORTANT)

28 дней назад
suse-cvrf логотип
SUSE-SU-2026:0258-1

Security update for libsoup2

17 дней назад
suse-cvrf логотип
SUSE-SU-2026:0253-1

Security update for libsoup2

17 дней назад
suse-cvrf логотип
SUSE-SU-2026:0257-1

Security update for libsoup

17 дней назад
suse-cvrf логотип
SUSE-SU-2026:0211-1

Security update for libsoup

18 дней назад

Уязвимостей на страницу