> USN-8780-1: libsoup vulnerabilities
[DATE: 17/09/2026 16:27]
[LANGUAGE: EN]
It was discovered that libsoup incorrectly handled certain URLs when
using an HTTP proxy. A remote attacker could possibly use this issue to
inject arbitrary HTTP headers. (CVE-2026-1467)
It was discovered that libsoup did not remove proxy authentication
credentials when following HTTP redirects. A remote attacker could
possibly use this issue to obtain sensitive information.
(CVE-2026-1539)
Ahmed Lekssays discovered that libsoup incorrectly parsed certain HTTP
requests. A remote attacker could possibly use this issue to obtain
sensitive information. (CVE-2026-1801)