CVE-2026-5119
published 2026-03-30CVE-2026-5119: A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the…
PriorityP345high8.2CVSS 3.1
AVNACLPRNUINSUCHILAN
EPSS
0.25%
16.8th percentile
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsoup2.4 | — | — |
| debian | libsoup3 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| ubuntu | libsoup2.4 | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
osv8.2HIGH
vendor_ubuntu9.1CRITICAL
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libsoup vulnerabilities
vendor_ubuntu·2026-07-09·CVSS 9.1
CVE-2026-2369 [CRITICAL] libsoup vulnerabilities
Title: libsoup vulnerabilities
Summary: Several security issues were fixed in libsoup.
Eric Su and Samuel Dainard discovered that libsoup incorrectly handled
content with zero-length resources. An attacker could possibly use this
issue to trigger a buffer over-read, resulting in information disclosure
or a denial of service. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and
Ubuntu 26.04 LTS. (CVE-2026-2369)
Kona Arctic discovered that libsoup did not properly protect sensitive
cookies when establishing HTTPS tunnels through an HTTP proxy. An
attacker could possibly use this issue to intercept session cookies,
resulting in session hijacking or user impersonation. (CVE-2026-5119)
Instructions: In general, a standard system
Red Hat
libsoup: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment
vendor_redhat·2026-03-30·CVSS 5.9
CVE-2026-5119 [MEDIUM] CWE-319 libsoup: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment
libsoup: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
Statement:
Debian
CVE-2026-5119: libsoup2.4 - A flaw was found in libsoup. When establishing HTTPS tunnels through a configure...
vendor_debian·2026·CVSS 5.9
CVE-2026-5119 [MEDIUM] CVE-2026-5119: libsoup2.4 - A flaw was found in libsoup. When establishing HTTPS tunnels through a configure...
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
Scope: local
bookworm: open
bullseye: open
trixie: open
VulDB
GNOME libsoup HTTP Proxy cleartext transmission (EUVD-2026-17062 / Nessus ID 309074)
vuldb·2026-05-17·CVSS 8.2
CVE-2026-5119 [HIGH] GNOME libsoup HTTP Proxy cleartext transmission (EUVD-2026-17062 / Nessus ID 309074)
A vulnerability was found in GNOME libsoup. It has been rated as problematic. The affected element is an unknown function of the component HTTP Proxy Handler. This manipulation causes cleartext transmission of sensitive information.
This vulnerability is handled as CVE-2026-5119. The attack can be initiated remotely. There is not any exploit available.
OSV
CVE-2026-5119: A flaw was found in libsoup
osv·2026-03-30·CVSS 8.2
CVE-2026-5119 [HIGH] CVE-2026-5119: A flaw was found in libsoup
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
GHSA
GHSA-j666-j6hj-fpc7: A flaw was found in libsoup
ghsa_unreviewed·2026-03-30
CVE-2026-5119 [MEDIUM] CWE-319 GHSA-j666-j6hj-fpc7: A flaw was found in libsoup
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-5119 libsoup3: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment [fedora-all]
bugzilla·2026-03-30·CVSS 8.2
CVE-2026-5119 [HIGH] CVE-2026-5119 libsoup3: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment [fedora-all]
CVE-2026-5119 libsoup3: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-37298d3095 (libsoup3-3.6.6-3.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-37298d3095
---
FEDORA-2026-37298d3095 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-37298d3095`
You can provide feed
Bugzilla
CVE-2026-5119 libsoup: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment
bugzilla·2026-03-30·CVSS 8.2
CVE-2026-5119 [HIGH] CVE-2026-5119 libsoup: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment
CVE-2026-5119 libsoup: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment
Cleartext Transmission of Sensitive Information has been reported in libsoup’s HTTP CONNECT handling. When establishing HTTPS tunnels via soup_session.c::tunnel_connect(), cookies (including potentially sensitive session cookies) are sent in cleartext within the initial HTTP CONNECT request to the configured proxy. A network-positioned attacker or malicious HTTP proxy can intercept or observe these cookies and leverage them for session hijacking or user impersonation.
Wiz
CVE-2026-5119 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-5119 [MEDIUM] CVE-2026-5119 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5119 :
Linux Debian vulnerability analysis and mitigation
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
Source : NVD
## 8.2
Score
Published March 30, 2026
Severity HIGH
CNA Score 5.9
Affected Technologies
Linux Debian
Linux Red Hat
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libsoup-devel
libsoup2.4
Sources
https://access.redhat.com/errata/RHSA-2026:13978https://access.redhat.com/errata/RHSA-2026:14087https://access.redhat.com/errata/RHSA-2026:15968https://access.redhat.com/errata/RHSA-2026:17482https://access.redhat.com/errata/RHSA-2026:19143https://access.redhat.com/errata/RHSA-2026:19356https://access.redhat.com/errata/RHSA-2026:21686https://access.redhat.com/errata/RHSA-2026:22316https://access.redhat.com/errata/RHSA-2026:22317https://access.redhat.com/errata/RHSA-2026:22323https://access.redhat.com/errata/RHSA-2026:22710https://access.redhat.com/errata/RHSA-2026:22716https://access.redhat.com/errata/RHSA-2026:24344https://access.redhat.com/errata/RHSA-2026:24722https://access.redhat.com/security/cve/CVE-2026-5119https://bugzilla.redhat.com/show_bug.cgi?id=2452932https://gitlab.gnome.org/GNOME/libsoup/-/issues/502
2026-03-30
Published