HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-5119 — A flaw was found in libsoup. When establishing HTTPS tunnels through a configure...
Monday, March 30, 2026 at 07:15 AM UTC·Source: NIST NVD
Updated: Monday, April 6, 2026 at 12:17 AM UTC
Executive Summary
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
Analysis
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.
CVSS Score: 5.9. Published: 2026-03-30T07:15:58.350.