CVE-2025-46421 Details
Description
A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.
A vulnerability exists in libsoup, an HTTP client and server library for GNOME. When libsoup clients encounter an HTTP redirect, they incorrectly send the Authorization header to the new host indicated by the redirect. This behavior allows the new host to impersonate the user to the original host that issued the redirect. This issue affects libsoup versions prior to 3.6.5.
Users can update to libsoup version 3.6.5 or later to address this vulnerability. Instructions for applying this update are available on the Red Hat Customer Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 24, 2025CISA-ADP
Assessed Apr 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| libsoup | All versions |
CPE
Remediation
| |
| Red Hat Enterprise Linux | All versions |
CPE
Remediation
| |
| Red Hat Enterprise Linux Server | All versions |
CPE
Remediation
| |
| Red Hat CodeReady Linux Builder | All versions |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jul 28, 2025 | CVE Modified | [email protected] |
| May 13, 2025 | CVE Modified | [email protected] |
| May 7, 2025 | CVE Modified | [email protected] |
| May 6, 2025 | CVE Modified | [email protected] |
| May 6, 2025 | CVE Modified | [email protected] |
| May 5, 2025 | CVE Modified | [email protected] |
| May 5, 2025 | CVE Modified | [email protected] |
| Apr 24, 2025 | New CVE Received | [email protected] |
Volerion