Medium severity6.5NVD Advisory· Published Jul 24, 2026· Updated Aug 24, 2026
CVE-2026-66339
CVE-2026-66339
Description
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2026-66339nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryExploitMitigation
News mentions
0No linked articles in our index yet.