CVE-2026-12547 LOW

CVE-2026-12547: Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch

Vendor Red Hat
Product Red Hat Enterprise Linux 10
Weakness CWE-201
Published July 21, 2026
Last update July 21, 2026

CVSS base score

3.4/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N

What the vulnerability does

01Description

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

Key dates

02Disclosure timeline

July 21, 2026 CVE published
July 21, 2026 Record updated

Related vulnerabilities

04Related CVE