CVE-2025-14523
Security update for libsoup2
Beschreibung
Ein Fehler in der HTTP-Header-Behandlung von libsoup ermöglicht mehrere `Host:`-Header in einer Anfrage und verwendet den letzten für die serverseitige Verarbeitung. Häufige Frontproxys beachten oft den ersten `Host:`-Header, was zu vhost-Konfusion führen kann, bei der ein Proxy eine Anfrage an einen Backend weiterleitet, aber dieser sie als für einen anderen Host bestimmt interpretiert. Diese Diskrepanz ermöglicht Angriffe im Stil von Request-Smuggling, Cache-Vergiftung oder das Umgehen hostbasierter Zugriffskontrollen, wenn ein Angreifer doppelte `Host`-Header bereitstellt.
Metriken
Weakness-Klassen (CWE)
CWE-444Base
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.
cwe.mitre.org →
Betroffene Betriebssysteme
linux
redhat / enterprise_linux10.0
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
gnome
libsoup
IBM
Power Hardware Management ConsoleV10
Red Hat
Enterprise Linux10
Red Hat
Enterprise Linux8
Red Hat
Enterprise Linux9
Red Hat
Enterprise Linuxlibsoup
Xerox
FreeFlow Print Serverv7
Quellen & Referenzen
- https://access.redhat.com/security/cve/CVE-2026-12548vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2489996issue-trackingx_refsource_REDHAT
- https://gitlab.gnome.org/GNOME/libsoup/-/work_items/512
- https://access.redhat.com/errata/RHSA-2025:4439vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:4440vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:4508vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:4538vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:4560vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:4568vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:4609vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:4624vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:7436vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:7505vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-46421vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2361962issue-trackingx_refsource_REDHAT
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/439
- https://access.redhat.com/security/cve/CVE-2025-46420vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2361963issue-trackingx_refsource_REDHAT
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/438
- https://access.redhat.com/errata/RHSA-2026:0421vendor-advisoryx_refsource_REDHAT