CVE-2026-3099Disclosure(gnome / enterprise_linux)

LOWCVSS 7.3 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute. This vulnerability allows a remote attacker to capture a single valid authentication header and replay it repeatedly. Consequently, the attacker can bypass authentication and gain unauthorized access to protected resources, impersonating the legitimate user.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-323

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • libsoup

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
enterprise_linuxlibsoup

6 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-13: 1Mentions · 2026-03-25: 1PoC Mentioned / Linked · 2026-03-25: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-25: 103-1303-25
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • WindowsForum@windowsforum
    Disclosure

    🚨 libsoup’s Digest auth replay bug = your “valid” login header becomes a reusable master key. If nonce-count isn’t enforced, Windows security is just vibes again. https://windowsforum.com/threads/cve-2026-3099-libsoup-digest-replay-bug-enables-authentication-bypass.407178/ #DigestAuthentication #LibsoupSecurity #Cve20263099 #ReplayAttack https://t.co/LG8LXCuOlr

    Post summary

    The post highlights a Disocvery of a libsoup Digest authentication replay bug that turns a valid login header into a reusable master key, but it provides no proof of active exploitation, patch information, or exploit code.

    0000045
    1.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3099 A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the… https://www.cve.org/CVERecord?id=CVE-2026-3099

    Post summary

    The post announces a flaw in Libsoup’s digest authentication where nonces are not correctly tracked, providing a brief technical description but no proof of concept, exploit, or vendor guidance.

    00000162
    56.7K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appgnomelibsoup---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--

Explore more