CVE-2025-14523

Updated: 2026-01-12 04:57:13.077183

Description:

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x HIGH 8.2

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU libsoup 2.72.0 8.2 HIGH Released CLSA-2026:1768566531 2026-01-16 16:04:52
CentOS 7 ELS libsoup 2.62.2 8.2 HIGH Released CLSA-2026:1769687040 2026-02-10 13:42:47
Oracle Linux 7 ELS libsoup 2.62.2 8.2 HIGH Released CLSA-2026:1769598671 2026-01-28 12:03:30
RHEL 7 ELS libsoup 2.62.2 8.2 HIGH Released CLSA-2026:1769598900 2026-01-28 12:03:28
TuxCare 9.6 ESU libsoup 2.72.0 8.2 HIGH Released CLSA-2026:1768555539 2026-01-16 16:04:51