CVE-2026-5119 Details
Description
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
A vulnerability in Libsoup allows sensitive session cookies to be transmitted in cleartext through the initial HTTP CONNECT request when establishing HTTPS tunnels via a configured HTTP proxy. This flaw can be exploited by a network-positioned attacker or a malicious HTTP proxy to intercept these cookies, potentially leading to session hijacking or user impersonation. The issue affects Libsoup versions prior to the latest commit in February 2026.
Users can mitigate this vulnerability by ensuring that all HTTP proxies used for HTTPS tunnels are trusted and operate within a secure network. Avoid configuring applications to use untrusted HTTP proxies. If possible, bypass proxies for sensitive connections or use a secure proxy solution that encrypts the entire communication channel.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gnome libsoup | All versions |
CPE
Remediation
| |
| redhat enterprise linux | 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | CVE Modified | [email protected] |
| Jun 8, 2026 | CVE Modified | [email protected] |
| Jun 3, 2026 | CVE Modified | [email protected] |
| Jun 3, 2026 | CVE Modified | [email protected] |
| Jun 1, 2026 | CVE Modified | [email protected] |
| Jun 1, 2026 | CVE Modified | [email protected] |
| Jun 1, 2026 | CVE Modified | [email protected] |
| May 28, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | [email protected] |
| May 14, 2026 | CVE Modified | [email protected] |
| May 11, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | CVE Modified | [email protected] |
| Apr 1, 2026 | Initial Analysis | [email protected] |
| Mar 30, 2026 | New CVE Received | [email protected] |