CVE-2026-12547 - Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch
CVE ID :CVE-2026-12547
Published : July 21, 2026, 6:35 p.m. | 14 minutes ago
Description :SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.
Severity: 3.4 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : July 21, 2026, 6:35 p.m. | 14 minutes ago
Description :SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.
Severity: 3.4 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...