HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-5119 — A flaw was found in libsoup. When establishing HTTPS tunnels through a configure...

Monday, March 30, 2026 at 07:15 AM UTC·Source: NIST NVD

Updated: Monday, April 6, 2026 at 12:17 AM UTC

Executive Summary

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.

Analysis

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation. CVSS Score: 5.9. Published: 2026-03-30T07:15:58.350.

Indicators of Compromise (1)

CVE (1)
CVE-2026-5119
Source Attribution

Originally published by NIST NVD on Mar 30, 2026. Verified by: NIST.

Related Threats