A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set cookies for domains it does not own, potentially leading to integrity issues such as session fixation.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | May 15, 2025 | Apr 29, 2025 |
| Oracle_linux | — | Upgrade libsoup3Upgrade libsoup3-develUpgrade libsoup3-doc | Jul 10, 2025 | Apr 28, 2025 |
| Redhat_linux | — | Upgrade libsoup3Upgrade libsoup3-debugsourceUpgrade libsoup3-develNo solution existsUpgrade libsoup3-docUpgrade libsoup3-debuginfo | Jul 9, 2025 | Apr 29, 2025 |
| Rocky_linux | — | Upgrade libsoup3-develUpgrade libsoup3-debugsourceUpgrade libsoup3-debuginfoUpgrade libsoup3 | Oct 6, 2025 | Oct 3, 2025 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Apr 29, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | Apr 29, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub