CVE Vulnerabilities

CVE-2026-5119

Cleartext Transmission of Sensitive Information

Published: Mar 30, 2026 | Modified: Jun 09, 2026
CVSS 3.x
8.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
LibsoupGnome- (including)- (including)
Enterprise_linuxRedhat7.0 (including)7.0 (including)
Enterprise_linuxRedhat8.0 (including)8.0 (including)
Enterprise_linuxRedhat9.0 (including)9.0 (including)
Enterprise_linuxRedhat10.0 (including)10.0 (including)
Red Hat Enterprise Linux 10RedHatlibsoup3-0:3.6.5-3.el10_1.11*
Red Hat Enterprise Linux 10RedHatlibsoup3-0:3.6.5-3.el10_2.11*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatlibsoup3-0:3.6.5-3.el10_0.15*
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatlibsoup-0:2.62.2-12.el7_9*
Red Hat Enterprise Linux 8RedHatlibsoup-0:2.62.3-14.el8_10*
Red Hat Enterprise Linux 8RedHatlibsoup-0:2.62.3-14.el8_10*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatlibsoup-0:2.62.3-2.el8_4.9*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatlibsoup-0:2.62.3-2.el8_4.9*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatlibsoup-0:2.62.3-2.el8_6.9*
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnRedHatlibsoup-0:2.62.3-2.el8_6.9*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatlibsoup-0:2.62.3-3.el8_8.9*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatlibsoup-0:2.62.3-3.el8_8.9*
Red Hat Enterprise Linux 9RedHatlibsoup-0:2.72.0-12.el9_7.6*
Red Hat Enterprise Linux 9RedHatlibsoup-0:2.72.0-16.el9_8.1*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatlibsoup-0:2.72.0-8.el9_0.10*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatlibsoup-0:2.72.0-8.el9_2.11*
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsRedHatlibsoup-0:2.72.0-8.el9_4.10*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatlibsoup-0:2.72.0-10.el9_6.7*
Libsoup2.4Ubuntuesm-infra/xenial*

Potential Mitigations

References