CVE-2025-4945 Details
Description
A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines.
A vulnerability has been identified in the libsoup HTTP library, which is utilized in GNOME applications and other software. This flaw arises from an integer overflow in the cookie parsing logic, specifically when processing expiration dates. A specially crafted cookie value can trigger this overflow, leading to undefined behavior. As a result, an attacker could manipulate cookie expiration logic, causing cookies to persist longer than intended or behave unpredictably. The issue originates from inadequate validation of large integer inputs during date calculations in the cookie parsing routines.
Red Hat advises avoiding interactions with untrusted or compromised HTTP servers until a patched version of libsoup is available. Users should monitor for suspicious HTTP activity and apply updates as soon as a fix is released.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 19, 2025CISA-ADP
Assessed Mar 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| libsoup | All versions |
CPE
Remediation
| |
| Red Hat Enterprise Linux | < 10 |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 19, 2026 | CVE Modified | CISA-ADP |
| Mar 19, 2026 | CVE Modified | [email protected] |
| Nov 25, 2025 | CVE Modified | [email protected] |
| Nov 19, 2025 | CVE Modified | [email protected] |
| Nov 18, 2025 | CVE Modified | [email protected] |
| Nov 18, 2025 | CVE Modified | [email protected] |
| Nov 11, 2025 | CVE Modified | [email protected] |
| Nov 4, 2025 | CVE Modified | [email protected] |
| Nov 4, 2025 | CVE Modified | [email protected] |
| May 19, 2025 | New CVE Received | [email protected] |
Volerion