cbcvebase.
CVE-2025-46421
published 2025-04-24

CVE-2025-46421: A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the…

PriorityP433medium6.8CVSS 3.1
AVNACHPRNUIRSUCHIHAN
EPSS
0.51%
39.9th percentile
A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianlibsoup2.4< libsoup3 3.2.3-0+deb12u1 (bookworm)libsoup3 3.2.3-0+deb12u1 (bookworm)
debianlibsoup3< libsoup3 3.2.3-0+deb12u1 (bookworm)libsoup3 3.2.3-0+deb12u1 (bookworm)
msrcazl3_libsoup_3.4.4-5_on_azure_linux_3.0
msrcazl3_libsoup_3.4.4-6_on_azure_linux_3.0
msrccbl2_libsoup_3.0.4-5_on_cbl_mariner_2.0
msrccbl2_libsoup_3.0.4-6_on_cbl_mariner_2.0

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.8MEDIUM
vendor_msrc6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.