CVE-2026-66339

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2026-66339 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2506951 Issue Tracking Vendor Advisory Exploit Mitigation
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnome:libsoup:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-24 23:16

Updated : 2026-08-24 16:44


NVD link : CVE-2026-66339

Mitre link : CVE-2026-66339

CVE.ORG link : CVE-2026-66339


JSON object : View

Products Affected

redhat

  • enterprise_linux

gnome

  • libsoup
CWE
CWE-201

Insertion of Sensitive Information Into Sent Data