Executive brief
libsoup is a networking library used by many applications to communicate over the internet. A flaw in how it handles secure connections through a proxy server causes it to accidentally share the user's proxy login credentials with the final destination website. This could allow a malicious website owner to steal a user's proxy username and password, potentially gaining unauthorized access to corporate or private network gateways.
Technical details
A vulnerability exists in libsoup's proxy authentication logic within auth_msg_starting() in libsoup/auth/soup-auth-manager.c. When an HTTP CONNECT tunnel is established, the library fails to verify if a request is being sent through an existing tunnel before attaching authentication headers. Consequently, the Proxy-Authorization header—which should only be present on the initial CONNECT request—is included in subsequent HTTPS requests sent to the destination server. While the data is protected by TLS from external eavesdroppers, the destination server itself can capture the proxy credentials in cleartext. This issue is tracked as CWE-201 (Insertion of Sensitive Information Into Sent Data).
Affected products
- Red Hat libsoup3 Enterprise Linux 10
- Red Hat libsoup Enterprise Linux 6, 7, 8, 9
Timeline
- 2026-07-24: disclosed: Initial report and CVE assignment by Red Hat
- 2026-07-24: advisory: NVD publication date