CVE-2026-1539

A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to third-party servers. Applications using libsoup for HTTP communication may unintentionally expose proxy authentication data.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2026-1539 Third Party Advisory
https://gitlab.gnome.org/GNOME/libsoup/-/issues/489 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnome:libsoup:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

25 Mar 2026, 14:08

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2026-1539 - () https://access.redhat.com/security/cve/CVE-2026-1539 - Third Party Advisory
References () https://gitlab.gnome.org/GNOME/libsoup/-/issues/489 - () https://gitlab.gnome.org/GNOME/libsoup/-/issues/489 - Issue Tracking, Vendor Advisory
CPE cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:gnome:libsoup:-:*:*:*:*:*:*:*
First Time Redhat
Gnome
Gnome libsoup
Redhat enterprise Linux

19 Mar 2026, 15:16

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en la librería HTTP libsoup que puede causar que las credenciales de autenticación de proxy se envíen a destinos no deseados. Al manejar redirecciones HTTP, libsoup elimina el encabezado Authorization pero no elimina el encabezado Proxy-Authorization si la solicitud es redirigida a un host diferente. Como resultado, las credenciales de proxy sensibles pueden filtrarse a servidores de terceros. Las aplicaciones que usan libsoup para comunicación HTTP pueden exponer involuntariamente datos de autenticación de proxy.
References
  • () https://gitlab.gnome.org/GNOME/libsoup/-/issues/489 -

28 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-28 16:16

Updated : 2026-03-25 14:08


NVD link : CVE-2026-1539

Mitre link : CVE-2026-1539

CVE.ORG link : CVE-2026-1539


JSON object : View

Products Affected

redhat

  • enterprise_linux

gnome

  • libsoup
CWE
CWE-201

Insertion of Sensitive Information Into Sent Data