Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 44 libsoup3 Critical Info Disclosure Patch CVE-2026-5119

fedora
Calendar Grey June 1, 2026
Dist Fedora Esm H88
Critical patch for libsoup3 on Fedora 44 addresses information disclosure through HTTPS cookie transmission. Learn more!
Patch for CVE-2026-5119

Summary

Libsoup is an HTTP library implementation in C. It was originally part

of a SOAP (Simple Object Access Protocol) implementation called Soup, but

the SOAP and non-SOAP parts have now been split into separate packages.

libsoup uses the Glib main loop and is designed to work well with GTK

applications. This enables GNOME applications to access HTTP servers

on the network in a completely asynchronous fashion, very similar to

the Gtk+ programming model (a synchronous operation mode is also

supported for those who want it), but the SOAP parts were removed

long ago.

Update Information:

Patch for CVE-2026-5119

Change Log

* Wed May 20 2026 Luigi Pavan - 3.6.6-8 - Fix CVE-2026-5119: cookies sent in cleartext to HTTP proxy for HTTPS requests * Mon Apr 27 2026 Michael Catanzaro - 3.6.6-7 - Tighten glib-networking dependency to Requires

References


[ 1 ] Bug #2452935 - CVE-2026-5119 libsoup3: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452935

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ce6cab40ac' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libsoup3
Product: Fedora 44
Version: 3.6.6
Release: 8.fc44
Summary: Soup, an HTTP library implementation

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here