CVE-2026-1539Disclosure(gnome / enterprise_linux)

LOWCVSS 5.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to third-party servers. Applications using libsoup for HTTP communication may unintentionally expose proxy authentication data.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-201

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • libsoup

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
enterprise_linuxlibsoup

6 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-28: 2Mentions · 2026-03-06: 1Technical Details · 2026-01-28: 2Technical Details · 2026-03-06: 101-2803-06
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-282
Disclosure2
2026-03-061
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1539 Proxy Authentication Credential Leak in libsoup HTTP Library Redirection Handling https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1539

    Post summary

    A newly disclosed CVE (CVE‑2026‑1539) reveals a credential leak vulnerability in the libsoup HTTP library during redirection handling.

    1001073
    4.0K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🚨 ALERT: Critical libsoup vulns (CVE-2026-1467, CVE-2026-1539, CVE-2026-1760) hit #SUSE/#openSUSE. Risks include HTTP request smuggling, credential leaks, and DoS. Read more: 👉 https://tinyurl.com/f3mdpcth #Security https://t.co/PF1PoLlVHQ

    Post summary

    The tweet alerts SUSE users to newly disclosed libsoup CVEs, outlining potential impact areas (request smuggling, credential leaks, DoS) but does not provide evidence of exploitation, PoC, or patch details.

    0001068
    1.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1539 A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsou… https://www.cve.org/CVERecord?id=CVE-2026-1539

    Post summary

    The statement discloses CVE-2026-1539, noting it allows proxy authentication credentials to be sent to unintended destinations when libsou handles HTTP redirects.

    00000163
    56.5K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appgnomelibsoup---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--

Explore more