Beveiligingsadvies

CVE-2026-66339

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-24 23:01:15
Laatst bijgewerkt 2026-07-28 14:55:26
Toegewezen door redhat
CVSS-score 6.5
Status PUBLISHED

Beschrijving

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure.