Security Advisory

CVE-2026-12547

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-21 18:35:53
Last updated 2026-07-21 19:14:49
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.