SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-66339

MEDIUM · CVSS 6.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

A vulnerability in libsoup allows the Proxy-Authorization header to be improperly attached to subsequent HTTPS requests after establishing a CONNECT tunnel via an HTTP proxy. This flaw can lead to the unintended disclosure of proxy credentials to the destination server, posing a risk of sensitive information exposure. Organizations utilizing libsoup in their applications should prioritize addressing this issue to mitigate potential credential leaks.

CVE
CVE-2026-66339
Severity
MEDIUM
CVSS
6.5
EPSS
0.23%

Original NVD Description

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure.