SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.
Metrics
Affected Vendors & Products
References
History
Mon, 27 Jul 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libsoup
Libsoup libsoup |
|
| Vendors & Products |
Libsoup
Libsoup libsoup |
Tue, 21 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials. | |
| Title | Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-201 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 | |
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-07-21T18:35:53.214Z
Updated: 2026-07-21T19:14:49.960Z
Reserved: 2026-06-17T18:09:30.319Z
Link: CVE-2026-12547
Updated: 2026-07-21T19:03:10.203Z
Status : Awaiting Analysis
Published: 2026-07-21T19:17:09.303
Modified: 2026-07-21T20:16:58.620
Link: CVE-2026-12547
No data.