VYPR
Unrated severityNVD Advisory· Published Jul 25, 2026

Debian libsoup2.4: A flaw was found in libsoup. After a CONNECT tunnel is established through an HT…

CVE-2026-66339

Description

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure.

Affected products

2

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.