CVE-2025-46421
6.8
MEDIUM
CVSS 3.1
EPSS 0.31%
Description
A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.
How to fix CVE-2025-46421
To remediate CVE-2025-46421, upgrade the affected package to a fixed version below.
- Debian/libsoup2.4—no fix listed
- —upgrade to 3.2.3-0+deb12u1 or later
Is CVE-2025-46421 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0
- from 0, < 3.2.3-0+deb12u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.8 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N |