CVE-2025-46421

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Apr 24, 2025
Updated: May 13, 2025
CWE ID 497

Summary

CVE-2025-46421 is a newly discovered vulnerability affecting libsoup, a popular library used in the GNOME desktop environment for handling HTTP and HTTPS communications. The issue arises when libsoup clients encounter an HTTP redirect; instead of removing the HTTP Authorization header during the redirection process, it is inadvertently sent to the new host. This mistake enables the new host to impersonate the user to the original host that issued the redirect, potentially leading to unauthorized access and data theft. Users and organizations are strongly advised to update their systems with the latest patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share