Information disclosure in libsoup - CVE-2025-4035
Published: May 29, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an error when handling cookies, as libsoup clients mistakenly allow cookies to be set for public suffix
domains if the domain contains at least two components and includes an
uppercase character. A remote attacker can set cookies for the domain they do not have access to and perform session fixation attacks.
Affected software
Anolis OS
libsoup3 (Red Hat package)
libsoup3
libsoup3-devel
libsoup3-doc
How to mitigate CVE-2025-4035
libsoup3 - update to 3.6.5-4
libsoup3-devel - update to 3.6.5-4
libsoup3-doc - update to 3.6.5-4