Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)
Summary
| CVE | CVE-2025-14523 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-12-11 13:15:58 UTC |
| Updated | 2026-06-25 02:16:34 UTC |
| Description | A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers. |
Risk And Classification
Primary CVSS: v3.1 8.2 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Problem Types: CWE-444 | CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 8.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
| 3.1 | CNA | CVSS | 8.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2026:1572 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:0908 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:1509 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:1571 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:0836 | [email protected] | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2025-14523 | [email protected] | access.redhat.com | |
| gitlab.gnome.org/GNOME/libsoup/-/issues/472 | [email protected] | gitlab.gnome.org | |
| access.redhat.com/errata/RHSA-2026:0422 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:0906 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:0905 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:0421 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:1569 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:0867 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:0909 | [email protected] | access.redhat.com | |
| bugzilla.redhat.com/show_bug.cgi | [email protected] | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2026:1570 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:0868 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:0911 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:0925 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:0423 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:0907 | [email protected] | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Red Hat would like to thank Ky0toFu and Sovereign Tech Resilience program for reporting this issue. (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2025-12-11T06:58:04.938Z | Reported to Red Hat. |
| CNA | 2025-12-11T00:00:00.000Z | Made public. |
Workarounds
CNA: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
There are currently no legacy QID mappings associated with this CVE.