Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2025-12111 | A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect. | 
|  Ubuntu USN | USN-7490-1 | libsoup vulnerabilities | 
|  Ubuntu USN | USN-7490-3 | libsoup vulnerabilities | 
Solution
No solution given by the vendor.
Workaround
Currently, no mitigation is available for this vulnerability.
Mon, 28 Jul 2025 13:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Wed, 14 May 2025 02:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:/a:redhat:enterprise_linux:9 | 
Tue, 13 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:/a:redhat:enterprise_linux:9::appstream cpe:/o:redhat:enterprise_linux:10.0 | |
| References |  | 
Wed, 07 May 2025 15:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:/a:redhat:enterprise_linux:8 cpe:/a:redhat:rhel_aus:8.2 cpe:/a:redhat:rhel_aus:8.4 cpe:/a:redhat:rhel_aus:8.6 cpe:/a:redhat:rhel_e4s:8.4 cpe:/a:redhat:rhel_e4s:8.6 cpe:/a:redhat:rhel_eus:8.8 cpe:/a:redhat:rhel_eus:9.2 cpe:/a:redhat:rhel_tus:8.4 cpe:/a:redhat:rhel_tus:8.6 cpe:/o:redhat:enterprise_linux:8 | 
Wed, 07 May 2025 08:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Redhat rhel Tus | |
| CPEs | cpe:/a:redhat:rhel_aus:8.4::appstream cpe:/a:redhat:rhel_aus:8.6::appstream cpe:/a:redhat:rhel_e4s:8.4::appstream cpe:/a:redhat:rhel_e4s:8.6::appstream cpe:/a:redhat:rhel_tus:8.4::appstream cpe:/a:redhat:rhel_tus:8.6::appstream cpe:/o:redhat:rhel_aus:8.4::baseos cpe:/o:redhat:rhel_aus:8.6::baseos cpe:/o:redhat:rhel_e4s:8.4::baseos cpe:/o:redhat:rhel_e4s:8.6::baseos cpe:/o:redhat:rhel_tus:8.4::baseos cpe:/o:redhat:rhel_tus:8.6::baseos | |
| Vendors & Products | Redhat rhel Tus | |
| References |  | 
Tue, 06 May 2025 20:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:/a:redhat:enterprise_linux:8::appstream cpe:/a:redhat:rhel_eus:8.8::appstream cpe:/a:redhat:rhel_eus:9.2::appstream cpe:/o:redhat:enterprise_linux:8::baseos cpe:/o:redhat:rhel_eus:8.8::baseos | |
| References |  | 
Tue, 06 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Redhat rhel Aus | |
| CPEs | cpe:/a:redhat:rhel_aus:8.2::appstream cpe:/o:redhat:rhel_aus:8.2::baseos | |
| Vendors & Products | Redhat rhel Aus | |
| References |  | 
Mon, 05 May 2025 15:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:/a:redhat:rhel_e4s:9.0 cpe:/a:redhat:rhel_eus:9.4 | 
Mon, 05 May 2025 02:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Redhat rhel Eus | |
| CPEs | cpe:/a:redhat:rhel_eus:9.4::appstream | |
| Vendors & Products | Redhat rhel Eus | |
| References |  | 
Mon, 05 May 2025 02:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Redhat rhel E4s | |
| CPEs | cpe:/a:redhat:rhel_e4s:9.0::appstream | |
| Vendors & Products | Redhat rhel E4s | |
| References |  | 
Fri, 25 Apr 2025 02:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | |
| Metrics | threat_severity 
 | threat_severity 
 | 
Thu, 24 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 24 Apr 2025 13:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect. | |
| Title | Libsoup: information disclosure may leads libsoup client sends authorization header to a different host when being redirected by a server | |
| First Time appeared | Redhat Redhat enterprise Linux | |
| Weaknesses | CWE-497 | |
| CPEs | cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 | |
| Vendors & Products | Redhat Redhat enterprise Linux | |
| References |  | |
| Metrics | cvssV3_1 
 | 
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-07-29T13:32:41.957Z
Reserved: 2025-04-24T01:37:42.413Z
Link: CVE-2025-46421
Updated: 2025-04-24T13:13:06.855Z
Status : Awaiting Analysis
Published: 2025-04-24T13:15:45.703
Modified: 2025-07-28T13:15:30.043
Link: CVE-2025-46421
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.