Medium severity5.8NVD Advisory· Published Mar 12, 2026· Updated Jun 17, 2026
CVE-2026-3099
CVE-2026-3099
Description
A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute. This vulnerability allows a remote attacker to capture a single valid authentication header and replay it repeatedly. Consequently, the attacker can bypass authentication and gain unauthorized access to protected resources, impersonating the legitimate user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:/o:redhat:enterprise_linux:10+ 9 more
- cpe:/o:redhat:enterprise_linux:10
- cpe:/o:redhat:enterprise_linux:6
- cpe:/o:redhat:enterprise_linux:7
- cpe:/o:redhat:enterprise_linux:8
- cpe:/o:redhat:enterprise_linux:9
- cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:gnome:libsoup:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- gitlab.gnome.org/GNOME/libsoup/-/issues/495nvdExploitIssue TrackingThird Party Advisory
- access.redhat.com/security/cve/CVE-2026-3099nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.