CVE-2026-5119General(gnome / enterprise_linux)

MEDIUMCVSS 8.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch gnome enterprise_linux systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or user impersonation.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-319

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • libsoup

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-30); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
enterprise_linuxlibsoup

5 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-30: 1Mentions · 2026-04-02: 1Mentions · 2026-06-04: 1PoC Mentioned / Linked · 2026-06-04: 1Exploit Tool / Code · 2026-06-04: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-06-04: 1Technical Details · 2026-03-30: 1Technical Details · 2026-04-02: 1Technical Details · 2026-06-04: 103-3004-0206-04
Signal classification3 categories
General
133.3%
Patch
133.3%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-301
General1
2026-04-021
Patch1
2026-06-041
PoC1
Full discourse3 posts
  • WindowsForum@windowsforum
    Patch

    🍪 Microsoft admins: turns out “encrypted” doesn’t help if your proxy setup leaks session cookies. CVE-2026-5119 = hijack-by-design vibes. Patch fast, folks. https://windowsforum.com/threads/cve-2026-5119-libsoup-cookie-leak-via-http-proxy-connect-enables-session-hijacking.409307/ #SessionHijacking #LibsoupVulnerability #HttpProxy #Cwe319InformationDisclosure https://t.co/QIdDvmZ5Kn

    Post summary

    The tweet urges Microsoft admins to patch CVE‑2026‑5119, a libsoup vulnerability that leaks session cookies through an HTTP proxy, enabling session hijacking; it does not provide a PoC, exploit code, or evidence of active exploitation.

    0101050
    1.0K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    PoC

    🐧 Falha CVE-2026-5119 no libsoup3: cookies são enviados em texto claro ao usar proxy HTTP. Guia completo com comandos, script e mitigações para o #Fedora. Saiba mais -> http://tinyurl.com/2x4tnf8y https://t.co/mNkTdfUEkI

    Post summary

    This tweet promotes a guide that includes a script and commands to demonstrate CVE‑2026‑5119 in libsoup3, along with mitigation steps, but does not report active exploitation or available vendor patches.

    1000050
    1.5K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5119 A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial … https://www.cve.org/CVERecord?id=CVE-2026-5119

    Post summary

    The CVE-2026-5119 vulnerability in libsoup leaks session cookies in cleartext when HTTPS is tunneled through a configured HTTP proxy.

    0000077
    56.9K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appgnomelibsoup---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--

Explore more