CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-12547

lowCVSS 3.4covered by 2 sourcesfirst seen 2026-07-14
SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.

CSIRTS triage

What
There is an information disclosure vulnerability in libsoup related to proxy credential leaks.
Who is affected
Applications using libsoup for HTTP requests.
Urgency
Remediation is important to protect sensitive information, with a low severity rating.
Action
Upgrade to the latest version of libsoup that resolves this issue.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-12547

Get an email if CVE-2026-12547 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-12547

CVE.org record

Embed the live status

CVE-2026-12547 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-12547 status](https://www.csirts.com/badge/CVE-2026-12547)](https://www.csirts.com/cve/CVE-2026-12547)