#VU109943 Information disclosure in libsoup - CVE-2025-4035

 

#VU109943 Information disclosure in libsoup - CVE-2025-4035

Published: May 29, 2025


Vulnerability identifier: #VU109943
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green
CVE-ID: CVE-2025-4035
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
libsoup
Software vendor:
Gnome Development Team

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to an error when handling cookies, as libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. A remote attacker can set cookies for the domain they do not have access to and perform session fixation attacks.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links