Junglewise Threat Intelligence

CVE-2026-66339: GNOME libsoup proxy credential leak in CONNECT tunnels

CVE-2026-66339 · Severity: medium · CVSS 6.5 · Published 2026-07-24

Vendors: Red Hat.

Executive brief

libsoup is a networking library used by many applications to communicate over the internet. A flaw in how it handles secure connections through a proxy server causes it to accidentally share the user's proxy login credentials with the final destination website. This could allow a malicious website owner to steal a user's proxy username and password, potentially gaining unauthorized access to corporate or private network gateways.

Technical details

A vulnerability exists in libsoup's proxy authentication logic within auth_msg_starting() in libsoup/auth/soup-auth-manager.c. When an HTTP CONNECT tunnel is established, the library fails to verify if a request is being sent through an existing tunnel before attaching authentication headers. Consequently, the Proxy-Authorization header—which should only be present on the initial CONNECT request—is included in subsequent HTTPS requests sent to the destination server. While the data is protected by TLS from external eavesdroppers, the destination server itself can capture the proxy credentials in cleartext. This issue is tracked as CWE-201 (Insertion of Sensitive Information Into Sent Data).

Affected products

  • Red Hat libsoup3 Enterprise Linux 10
  • Red Hat libsoup Enterprise Linux 6, 7, 8, 9

Timeline

  • 2026-07-24: disclosed: Initial report and CVE assignment by Red Hat
  • 2026-07-24: advisory: NVD publication date

References