Libsoup: information disclosure may leads libsoup client sends authorization header to a different host when being redirected by a server
Summary
| CVE | CVE-2025-46421 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-04-24 13:15:45 UTC |
| Updated | 2026-06-30 05:17:23 UTC |
| Description | A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect. |
Risk And Classification
Primary CVSS: v3.1 6.8 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS: 0.004780000 probability, percentile 0.378410000 (date 2026-07-04)
Problem Types: CWE-497 | CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 6.8 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N |
| 3.1 | CNA | CVSS | 6.8 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Red Hat Enterprise Linux 10 | unaffected 0:3.6.5-3.el10_0 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | unaffected 0:2.62.3-8.el8_10 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | unaffected 0:2.62.3-8.el8_10 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.2 Advanced Update Support | unaffected 0:2.62.3-1.el8_2.4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | unaffected 0:2.62.3-2.el8_4.4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | unaffected 0:2.62.3-2.el8_4.4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Update Services For SAP Solutions | unaffected 0:2.62.3-2.el8_4.4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | unaffected 0:2.62.3-2.el8_6.4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Telecommunications Update Service | unaffected 0:2.62.3-2.el8_6.4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions | unaffected 0:2.62.3-2.el8_6.4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | unaffected 0:2.62.3-3.el8_8.4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:2.72.0-10.el9_6.1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions | unaffected 0:2.72.0-8.el9_0.4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | unaffected 0:2.72.0-8.el9_2.4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | unaffected 0:2.72.0-8.el9_4.4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 6 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 7 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2025:4439 | [email protected] | access.redhat.com | |
| bugzilla.redhat.com/show_bug.cgi | [email protected] | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2025:4624 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:4538 | [email protected] | access.redhat.com | |
| gitlab.gnome.org/GNOME/libsoup/-/issues/439 | [email protected] | gitlab.gnome.org | |
| access.redhat.com/errata/RHSA-2025:4508 | [email protected] | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2025-46421 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:4609 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:4440 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:7505 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:7436 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:4560 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:4568 | [email protected] | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2025-04-24T01:35:00.884Z | Reported to Red Hat. |
| CNA | 2025-04-24T00:00:00.000Z | Made public. |
Workarounds
CNA: Currently, no mitigation is available for this vulnerability.
There are currently no legacy QID mappings associated with this CVE.