What is CVE-2026-66339?
A flaw in libsoup causes the Proxy-Authorization header to be incorrectly sent to the destination server after a CONNECT tunnel is established through an HTTP proxy. This could allow the destination server to capture proxy credentials. Affected systems should update libsoup to the latest patched version.
Azərbaycanca: libsoup kitabxanasında aşkarlanan bu boşluq, HTTP proxy vasitəsilə CONNECT tuneli qurulduqdan sonra Proxy-Authorization başlığının səhvən hədəf serverə göndərilməsinə səbəb olur. Bu, hədəf serverin proxy etimadnamələrini ələ keçirməsinə imkan yaradır. Təsirə məruz qalan sistemlərdə libsoup-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
How can CVE-2026-66339 be exploited?
After a CONNECT tunnel is established through an HTTP proxy, the Proxy-Authorization header is incorrectly sent to the destination server, allowing the destination server to capture proxy credentials.
How can I mitigate CVE-2026-66339?
Affected systems should update the libsoup library to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.