Libsoup: improper handling of http vary header in libsoup caching
Published Sep 3, 2025
5.9
MEDIUMCVSS 3.1
EPSS 0.45%
Description
A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached responses. This header ensures that responses vary appropriately based on request headers such as language or authentication. Without this check, cached content can be incorrectly reused across different requests, potentially exposing sensitive user information. While the issue is unlikely to affect everyday desktop use, it could result in confidentiality breaches in proxy or multi-user environments.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
libsoup3
Fix deferred
Red Hat Enterprise Linux 6
libsoup
Out of support scope
Red Hat Enterprise Linux 7
libsoup
Fix deferred
Red Hat Enterprise Linux 8
libsoup
Fix deferred
Red Hat Enterprise Linux 9
libsoup
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | libsoup3 | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | libsoup | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libsoup | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | libsoup | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | libsoup | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet Red Hat Product Security criteria comprising ease of use, deployment applicability to widespread installations, or stability. Administrators should apply vendor-supplied patches once they become available.
Red Hat statement
The Red Hat Product Security team has rated this vulnerability as a Moderate severity, since exploitation requires uncommon deployment conditions such as an application enabling SoupCache in a proxy-like configuration. In the worst case scenario, cached responses containing confidential data may be served to unintended users, leading to significant information disclosure. Standard GNOME desktop applications are not affected under normal use.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet Red Hat Product Security criteria comprising ease of use, deployment applicability to widespread installations, or stability. Administrators should apply vendor-supplied patches once they become available.
References (5)
- https://access.redhat.com/security/cve/CVE-2025-9901 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2392790 issue-trackingx_refsource_REDHATIssue Tracking
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/453
- https://nvd.nist.gov/vuln/detail/CVE-2025-9901
- https://www.cve.org/CVERecord?id=CVE-2025-9901
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-9901 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2392790 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://gitlab.gnome.org/GNOME/libsoup/-/issues/453 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2025-9901 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-9901 |
Change history (0)
No recorded changes yet.