CVE-2026-5119
MEDIUM
5,9
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: low
Availability: none
Description
AI Translation Available
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
319
Cleartext Transmission of Sensitive Information
DraftCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Potential Impacts:
Read Application Data
Modify Files Or Directories
Other
Applicable Platforms
Technologies:
Cloud Computing, ICS/OT, Mobile, Not Technology-Specific, System on Chip, Test/Debug Hardware
https://access.redhat.com/security/cve/CVE-2026-5119
https://bugzilla.redhat.com/show_bug.cgi?id=2452932
https://gitlab.gnome.org/GNOME/libsoup/-/issues/502