Back

MEDIUM

Libsoup: improper handling of http vary header in libsoup caching

Published Sep 3, 2025

Description

A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached responses. This header ensures that responses vary appropriately based on request headers such as language or authentication. Without this check, cached content can be incorrectly reused across different requests, potentially exposing sensitive user information. While the issue is unlikely to affect everyday desktop use, it could result in confidentiality breaches in proxy or multi-user environments.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options do not meet Red Hat Product Security criteria comprising ease of use, deployment applicability to widespread installations, or stability. Administrators should apply vendor-supplied patches once they become available.

Red Hat statement

The Red Hat Product Security team has rated this vulnerability as a Moderate severity, since exploitation requires uncommon deployment conditions such as an application enabling SoupCache in a proxy-like configuration. In the worst case scenario, cached responses containing confidential data may be served to unintended users, leading to significant information disclosure. Standard GNOME desktop applications are not affected under normal use.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet Red Hat Product Security criteria comprising ease of use, deployment applicability to widespread installations, or stability. Administrators should apply vendor-supplied patches once they become available.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 3, 2025
Updated Jun 30, 2026
Reserved Sep 3, 2025
CISA Vulnrichment
Updated Sep 3, 2025
NVD
Status Deferred
Modified Jun 30, 2026
Red Hat
Severity Moderate
Public date Sep 3, 2025