Unrated severityNVD Advisory· Published Jul 25, 2026
Debian libsoup2.4: A flaw was found in libsoup. After a CONNECT tunnel is established through an HT…
CVE-2026-66339
Description
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure.
Affected products
2Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.