TROYANOSYVIRUS
Retour aux CVEs

CVE-2026-1539

MEDIUM
5.8

Description

A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to third-party servers. Applications using libsoup for HTTP communication may unintentionally expose proxy authentication data.

Details CVE

Score CVSS v3.15.8
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie1/28/2026
Derniere modification3/25/2026
Sourcenvd
Observations honeypot0

Produits affectes

gnome:libsoupredhat:enterprise_linux

Faiblesses (CWE)

CWE-201

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.