CVE-2025-4476 Details
Description
A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. An attacker could exploit this by setting up a malicious HTTP server. If a user's application using the vulnerable libsoup library connects to this malicious server, it could result in a denial-of-service. Successful exploitation requires tricking a user's client application into connecting to the attacker's malicious server.
A denial-of-service vulnerability exists in the libsoup HTTP client library. This issue arises when a libsoup client processes a 401 (Unauthorized) HTTP response that contains a specially crafted domain parameter in the WWW-Authenticate header. The improper handling of this malformed header can cause the client application to crash. An attacker could exploit this vulnerability by setting up a malicious HTTP server. If a user's application, which uses the vulnerable version of libsoup, connects to this server, it could lead to a denial-of-service condition. Exploitation requires deceiving the user into connecting to the attacker's server.
Red Hat advises against connecting applications that use libsoup to untrusted HTTP servers until an update is available. Users can check the Red Hat Product Security page for errata notifications and support options.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 16, 2025CISA-ADP
Assessed May 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitlab.gnome.org/GNOME/libsoup/-/work_items/440 | CISA-ADP | |
| https://access.redhat.com/security/cve/CVE-2025-4476 | [email protected] | AdvisoryRemedyVendor |
| https://bugzilla.redhat.com/show_bug.cgi?id=2366513 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://gitlab.gnome.org/GNOME/libsoup/-/issues/440 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| libsoup | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 6, 2026 | CVE Modified | CISA-ADP |
| May 6, 2026 | CVE Modified | [email protected] |
| May 16, 2025 | New CVE Received | [email protected] |
Volerion