CVE-2025-46421

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.
CVSS

No CVSS.

Configurations

No configuration.

History

28 Jul 2025, 13:15

Type Values Removed Values Added
References
  • () https://gitlab.gnome.org/GNOME/libsoup/-/issues/439 -

13 May 2025, 21:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:7505 -
  • () https://access.redhat.com/errata/RHSA-2025:7436 -

07 May 2025, 09:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:4609 -
  • () https://access.redhat.com/errata/RHSA-2025:4624 -

06 May 2025, 21:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:4560 -
  • () https://access.redhat.com/errata/RHSA-2025:4568 -
  • () https://access.redhat.com/errata/RHSA-2025:4508 -

06 May 2025, 14:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:4538 -

05 May 2025, 03:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:4440 -
  • () https://access.redhat.com/errata/RHSA-2025:4439 -
CVSS v2 : unknown
v3 : 6.8
v2 : unknown
v3 : unknown
CWE CWE-497

24 Apr 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-24 13:15

Updated : 2025-07-28 13:15


NVD link : CVE-2025-46421

Mitre link : CVE-2025-46421


JSON object : View

Products Affected

No product.

CWE

No CWE.