Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
If changing desktop proxy settings, close any applications using libsoup, then restart the application after the setting has been changed.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 27 Jul 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libsoup
Libsoup libsoup |
|
| Vendors & Products |
Libsoup
Libsoup libsoup |
Tue, 21 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials. | |
| Title | Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-201 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 | |
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-07-21T19:14:49.960Z
Reserved: 2026-06-17T18:09:30.319Z
Link: CVE-2026-12547
Updated: 2026-07-21T19:03:10.203Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T17:00:07Z
-
CWE-201
Insertion of Sensitive Information Into Sent Data