CVE-2026-1539
published 2026-01-28CVE-2026-1539: A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP…
PriorityP434medium5.8CVSS 3.1
AVNACLPRNUINSCCLINAN
EPSS
0.24%
14.7th percentile
A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to third-party servers. Applications using libsoup for HTTP communication may unintentionally expose proxy authentication data.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsoup2.4 | < libsoup3 3.6.5-8 (forky) | libsoup3 3.6.5-8 (forky) |
| debian | libsoup3 | < libsoup3 3.6.5-8 (forky) | libsoup3 3.6.5-8 (forky) |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libsoup3 vulnerabilities
osv·2026-02-08·CVSS 5.3
CVE-2026-1467 [MEDIUM] libsoup3 vulnerabilities
libsoup3 vulnerabilities
It was discovered that libsoup did not correctly handle certain
URL-decoded input, which could allow for HTTP header injection. A remote
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-1467, CVE-2026-1536)
It was discovered that libsoup did not correctly handle removal of the
Proxy-Authorization header. A remote attacker could possibly use this
issue to leak sensitive information. (CVE-2026-1539)
OSV
CVE-2026-1539: A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations
osv·2026-01-28·CVSS 5.8
CVE-2026-1539 [MEDIUM] CVE-2026-1539: A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations
A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to third-party servers. Applications using libsoup for HTTP communication may unintentionally expose proxy authentication data.
GHSA
GHSA-wj9p-f539-2mhr: A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations
ghsa_unreviewed·2026-01-28
CVE-2026-1539 [MEDIUM] CWE-201 GHSA-wj9p-f539-2mhr: A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations
A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to third-party servers. Applications using libsoup for HTTP communication may unintentionally expose proxy authentication data.
Ubuntu
libsoup vulnerabilities
vendor_ubuntu·2026-02-08·CVSS 5.8
CVE-2026-1539 [MEDIUM] libsoup vulnerabilities
Title: libsoup vulnerabilities
Summary: Several security issues were fixed in libsoup.
It was discovered that libsoup did not correctly handle certain
URL-decoded input, which could allow for HTTP header injection. A remote
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-1467, CVE-2026-1536)
It was discovered that libsoup did not correctly handle removal of the
Proxy-Authorization header. A remote attacker could possibly use this
issue to leak sensitive information. (CVE-2026-1539)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
CVE-2026-1539: A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations
vendor_redhat·2026-01-28·CVSS 5.8
CVE-2026-1539 [MEDIUM] CWE-201 CVE-2026-1539: A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations
A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to third-party servers. Applications using libsoup for HTTP communication may unintentionally expose proxy authentication data.
A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a res
Debian
CVE-2026-1539: libsoup2.4 - A flaw was found in the libsoup HTTP library that can cause proxy authentication...
vendor_debian·2026·CVSS 5.8
CVE-2026-1539 [MEDIUM] CVE-2026-1539: libsoup2.4 - A flaw was found in the libsoup HTTP library that can cause proxy authentication...
A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to third-party servers. Applications using libsoup for HTTP communication may unintentionally expose proxy authentication data.
Scope: local
bookworm: open
bullseye: open
trixie: open
No detection rules found.
No public exploits indexed.
2026-01-28
Published