CVE-2026-66339

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure.
Configurations

No configuration.

History

24 Jul 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-24 23:16

Updated : 2026-07-28 16:20


NVD link : CVE-2026-66339

Mitre link : CVE-2026-66339

CVE.ORG link : CVE-2026-66339


JSON object : View

Products Affected

No product.

CWE
CWE-201

Insertion of Sensitive Information Into Sent Data