CVE-2025-14523

Public on 2025-12-11
Modified on 2025-12-11
Description
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
8.2
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core libsoup 2026-02-05 ALAS2-2026-3142 Fixed
Amazon Linux 2023 libsoup 2026-02-05 ALAS2023-2026-1391 Fixed
Amazon Linux 2023 libsoup3 2026-02-05 ALAS2023-2026-1394 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N