A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached responses. This header ensures that responses vary appropriately based on request headers such as language or authentication. Without this check, cached content can be incorrectly reused across different requests, potentially exposing sensitive user information. While the issue is unlikely to affect everyday desktop use, it could result in confidentiality breaches in proxy or multi-user environments.
History

Wed, 03 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Sep 2025 13:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached responses. This header ensures that responses vary appropriately based on request headers such as language or authentication. Without this check, cached content can be incorrectly reused across different requests, potentially exposing sensitive user information. While the issue is unlikely to affect everyday desktop use, it could result in confidentiality breaches in proxy or multi-user environments.
Title libsoup: Improper Handling of HTTP Vary Header in libsoup Caching Libsoup: improper handling of http vary header in libsoup caching
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References

Wed, 03 Sep 2025 12:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title libsoup: Improper Handling of HTTP Vary Header in libsoup Caching
Weaknesses CWE-524
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-09-03T14:01:56.925Z

Reserved: 2025-09-03T05:04:55.177Z

Link: CVE-2025-9901

cve-icon Vulnrichment

Updated: 2025-09-03T14:01:34.733Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-03T13:15:50.133

Modified: 2025-09-04T15:36:56.447

Link: CVE-2025-9901

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-09-03T00:00:00Z

Links: CVE-2025-9901 - Bugzilla

cve-icon OpenCVE Enrichment

No data.