AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-9901

MEDIUM · CVSS 5.9 EPSS 0.43%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-09-03 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.9. See the original NVD description below for full technical details.

CVE
CVE-2025-9901
Severity
MEDIUM
CVSS
5.9
EPSS
0.43%

Original NVD Description

A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached responses. This header ensures that responses vary appropriately based on request headers such as language or authentication. Without this check, cached content can be incorrectly reused across different requests, potentially exposing sensitive user information. While the issue is unlikely to affect everyday desktop use, it could result in confidentiality breaches in proxy or multi-user environments.