CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-9901: Libsoup: improper handling of http vary header in libsoup caching

mediumCVSS 5.9CVE-2025-9901

CSIRTS triage

What
Improper handling of the HTTP Vary header in libsoup caching allows cache confusion or bypass.
Who is affected
Applications using libsoup for HTTP caching with malformed or malicious Vary headers.
Urgency
Medium priority with a CVSS score of 5.9; not yet exploited.
Action
Update libsoup to the patched version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch libsoup

Get an email when a new libsoup advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
medium — CVSS 5.9
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-9901

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-9901coverage & exploitation statusNVD · CVE.org

Recent advisories for Libsoup

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from Microsoft Security Response Center