A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set cookies for domains it does not own, potentially leading to integrity issues such as session fixation.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 29 Apr 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set cookies for domains it does not own, potentially leading to integrity issues such as session fixation. |
Title | libsoup: Cookie domain validation bypass via uppercase characters in libsoup | Libsoup: cookie domain validation bypass via uppercase characters in libsoup |
First Time appeared |
Redhat
Redhat enterprise Linux |
|
CPEs | cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
Vendors & Products |
Redhat
Redhat enterprise Linux |
|
References |
|
Mon, 28 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | |
Title | libsoup: Cookie domain validation bypass via uppercase characters in libsoup | |
Weaknesses | CWE-178 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published: 2025-04-29T12:56:22.726Z
Updated: 2025-04-29T13:18:21.297Z
Reserved: 2025-04-28T06:04:50.855Z
Link: CVE-2025-4035

Updated: 2025-04-29T13:18:18.722Z

Status : Awaiting Analysis
Published: 2025-04-29T13:15:45.407
Modified: 2025-04-29T13:52:10.697
Link: CVE-2025-4035
