CVE-2026-12547: Insertion of Sensitive Information Into Sent Data in Red Hat Red Hat Enterprise Linux 10
SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.
AI Analysis
Technical Summary
The vulnerability involves SoupAuthManager caching proxy authentication credentials globally rather than scoping them to the specific proxy authority. When the system's proxy configuration changes, such as through system settings or WPAD, the cached Proxy-Authorization headers from the previous proxy are sent to the new proxy. This behavior can lead to the unintended disclosure of sensitive authentication credentials to an unauthorized proxy. The CVSS 3.1 base score is 3.4 (low), reflecting network attack vector, low complexity, high privileges required, user interaction required, scope changed, and limited confidentiality impact. The vendor advisory does not specify a remediation or patch status.
Potential Impact
The impact is limited to the potential leakage of proxy authentication credentials to an unintended proxy server when proxy settings change. This could allow an attacker controlling the new proxy to obtain sensitive credentials. There is no impact on integrity or availability. The vulnerability requires high privileges and user interaction, reducing exploitation likelihood. No known exploits have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-12547 for current remediation guidance. Until an official fix is available, users should carefully manage proxy configurations and avoid frequent or automatic proxy changes that could trigger credential leakage. Monitor vendor updates for patches or workarounds.
CVE-2026-12547: Insertion of Sensitive Information Into Sent Data in Red Hat Red Hat Enterprise Linux 10
Description
SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.
CVSS v3.1
Score 3.4low
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability involves SoupAuthManager caching proxy authentication credentials globally rather than scoping them to the specific proxy authority. When the system's proxy configuration changes, such as through system settings or WPAD, the cached Proxy-Authorization headers from the previous proxy are sent to the new proxy. This behavior can lead to the unintended disclosure of sensitive authentication credentials to an unauthorized proxy. The CVSS 3.1 base score is 3.4 (low), reflecting network attack vector, low complexity, high privileges required, user interaction required, scope changed, and limited confidentiality impact. The vendor advisory does not specify a remediation or patch status.
Potential Impact
The impact is limited to the potential leakage of proxy authentication credentials to an unintended proxy server when proxy settings change. This could allow an attacker controlling the new proxy to obtain sensitive credentials. There is no impact on integrity or availability. The vulnerability requires high privileges and user interaction, reducing exploitation likelihood. No known exploits have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-12547 for current remediation guidance. Until an official fix is available, users should carefully manage proxy configurations and avoid frequent or automatic proxy changes that could trigger credential leakage. Monitor vendor updates for patches or workarounds.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-06-17T18:09:30.319Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-12547","vendor":"Red Hat"}]
Threat ID: 6a5fbd912a4a8d5989977fdc
Added to database: 07/21/2026, 18:42:25 UTC
Last enriched: 07/21/2026, 18:57:31 UTC
Last updated: 07/21/2026, 21:09:46 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.