CVE-2026-12547
3.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N
Summary
SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-201: Insertion of Sensitive Information Into Sent Data
Workarounds
If changing desktop proxy settings, close any applications using libsoup, then restart the application after the setting has been changed.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://access.redhat.com/security/cve/CVE-2026-12547
- https://bugzilla.redhat.com/show_bug.cgi?id=2489994
- https://gitlab.gnome.org/GNOME/libsoup/-/work_items/506
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.