CVE-2025-14523
published 2025-12-11CVE-2025-14523: A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front…
PriorityP351high8.2CVSS 3.1
AVNACLPRNUINSUCLIHAN
EPSS
0.51%
39.7th percentile
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsoup2.4 | < libsoup3 3.6.5-7 (forky) | libsoup3 3.6.5-7 (forky) |
| debian | libsoup3 | < libsoup3 3.6.5-7 (forky) | libsoup3 3.6.5-7 (forky) |
| msrc | azl3_libsoup_3.4.4-10_on_azure_linux_3.0 | — | — |
| msrc | azl3_libsoup_3.4.4-11_on_azure_linux_3.0 | — | — |
| msrc | azl3_libsoup_3.4.4-12_on_azure_linux_3.0 | — | — |
| msrc | azl3_libsoup_3.4.4-14_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libsoup_3.0.4-10_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libsoup_3.0.4-12_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libsoup_3.0.4-13_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
osv8.2HIGH
vendor_debian8.2HIGH
vendor_msrc8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libsoup: libsoup: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (First- vs Last-Value Wins)
vendor_redhat·2025-12-11·CVSS 8.2
CVE-2025-14523 [HIGH] CWE-444 libsoup: libsoup: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (First- vs Last-Value Wins)
libsoup: libsoup: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (First- vs Last-Value Wins)
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often hon
Microsoft
Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)
vendor_msrc·2025-12-09·CVSS 8.2
CVE-2025-14523 [HIGH] CWE-444 Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)
Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Debian
CVE-2025-14523: libsoup2.4 - A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a requ...
vendor_debian·2025·CVSS 8.2
CVE-2025-14523 [HIGH] CVE-2025-14523: libsoup2.4 - A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a requ...
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.
Scope: local
bookworm: open
bullseye: open
trixie: open
OSV
CVE-2025-14523: A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing
osv·2025-12-11·CVSS 8.2
CVE-2025-14523 [HIGH] CVE-2025-14523: A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.
GHSA
GHSA-4qpp-gxm3-h9vw: A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing
ghsa_unreviewed·2025-12-11
CVE-2025-14523 [HIGH] CWE-444 GHSA-4qpp-gxm3-h9vw: A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-14523 libsoup: libsoup: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (First- vs Last-Value Wins) [fedora-42]
bugzilla·2025-12-11·CVSS 8.2
CVE-2025-14523 [HIGH] CVE-2025-14523 libsoup: libsoup: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (First- vs Last-Value Wins) [fedora-42]
CVE-2025-14523 libsoup: libsoup: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (First- vs Last-Value Wins) [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 202
Wiz
CVE-2025-14523 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2025-14523 [HIGH] CVE-2025-14523 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14523 :
Rocky Linux vulnerability analysis and mitigation
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.
Source : NVD
## 8.2
Score
Published December 11, 2025
Severity HIGH
CNA Score 8.2
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
https://access.redhat.com/errata/RHSA-2026:0421https://access.redhat.com/errata/RHSA-2026:0422https://access.redhat.com/errata/RHSA-2026:0423https://access.redhat.com/errata/RHSA-2026:0836https://access.redhat.com/errata/RHSA-2026:0867https://access.redhat.com/errata/RHSA-2026:0868https://access.redhat.com/errata/RHSA-2026:0905https://access.redhat.com/errata/RHSA-2026:0906https://access.redhat.com/errata/RHSA-2026:0907https://access.redhat.com/errata/RHSA-2026:0908https://access.redhat.com/errata/RHSA-2026:0909https://access.redhat.com/errata/RHSA-2026:0911https://access.redhat.com/errata/RHSA-2026:0925https://access.redhat.com/errata/RHSA-2026:1509https://access.redhat.com/errata/RHSA-2026:1569https://access.redhat.com/errata/RHSA-2026:1570https://access.redhat.com/errata/RHSA-2026:1571https://access.redhat.com/errata/RHSA-2026:1572https://access.redhat.com/security/cve/CVE-2025-14523https://bugzilla.redhat.com/show_bug.cgi?id=2421349https://gitlab.gnome.org/GNOME/libsoup/-/issues/472
2025-12-11
Published