Skip to main content

Threats Tagged 'cve-2025-14523'

View all threats tagged with 'cve-2025-14523'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-14523

Threats Tagged 'cve-2025-14523'

Click on any threat for detailed analysis and mitigation recommendations

0

Multiple security vulnerabilities have been addressed in libsoup 3.6.6, an HTTP library used in GNOME applications. The fixes cover issues such as heap use-after-free, duplicate Host header handling, denial of service against websocket servers, input sanitization flaws, proxy authentication credential leaks, HTTP request smuggling, buffer overreads, and out-of-bounds reads. These vulnerabilities could lead to memory corruption, denial of service, information disclosure, or unauthorized HTTP requests. The update is available for Red Hat Enterprise Linux 10 and related products.

Join the discussion
0

This update for libsoup2 fixes the following issues: - CVE-2025-4476: null pointer dereference may lead to denial of service (bsc#1243422). - CVE-2025-14523: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (bsc#1254876). - CVE-2025-32049: Denial of Service attack to websocket server (bsc#1240751). - CVE-2026-0716: improper bounds handling may allow out-of-bounds read (bsc#1256418). - CVE-2026-0719: stack-based buffer overflow in NTLM authentication can lead to arbitrary code execution (bsc#1256399). - CVE-2026-1467: lack of input sanitization can lead to unintended or unauthorized HTTP requests (bsc#1257398). - CVE-2026-1539: proxy authentication credentials leaked via the Proxy-Authorization header when handling HTTP redirects (bsc#1257441). - CVE-2026-1760: improper handling of HTTP requests combining certain headers by SoupServer can lead to HTTP request smuggling and potential DoS (bsc#1257597). - CVE-2026-2369: Buffer overread due to integer underflow when handling zero-length resources (bsc#1258120). - CVE-2026-2443: out-of-bounds read when processing specially crafted HTTP Range headers can lead to heap information disclosure to remote attackers (bsc#1258170). - CVE-2026-2708: HTTP request smuggling via duplicate Content-Length headers (bsc#1258508).

Join the discussion

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: cve-2025-14523
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses