Information disclosure in libsoup - CVE-2025-4035

 

Information disclosure in libsoup - CVE-2025-4035

Published: May 29, 2025


Vulnerability identifier: #VU109943
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2025-4035
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to an error when handling cookies, as libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. A remote attacker can set cookies for the domain they do not have access to and perform session fixation attacks.


Affected software

libsoup
Anolis OS
libsoup3 (Red Hat package)
libsoup3
libsoup3-devel
libsoup3-doc

How to mitigate CVE-2025-4035

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

libsoup3 (Red Hat package) - update to 3.6.5-3.el10_0.6
libsoup3 - update to 3.6.5-4
libsoup3-devel - update to 3.6.5-4
libsoup3-doc - update to 3.6.5-4

External References

Related Security Bulletins