CVE-2026-5119 details a critical vulnerability in libsoup, impacting gnome and Red Hat Enterprise Linux products, where sensitive session cookies are transmitted in cleartext when establishing HTTPS tunnels via an HTTP proxy. Rated 8.2 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N), this flaw allows a network-positioned attacker or malicious proxy to intercept these cookies with low attack complexity, potentially leading to session hijacking or user impersonation. Currently, there is no evidence of active exploitation, public exploit code, or inclusion on the KEV catalog, though it has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:gnome:libsoup:-:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
libsoup vulnerabilities
Jul 9, 2026libsoup: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment
Mar 30, 2026Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment
Mar 10, 2026