Gnome · Libsoup · CVE-2026-1539
**Name of the Vulnerable Software and Affected Versions**
libsoup (affected versions not specified)
**Description**
An issue exists in the libsoup HTTP library where proxy authentication credentials can be sent to unintended destinations. This occurs because, during HTTP redirects to a different host, the library removes the Authorization header but fails to remove the Proxy-Authorization header. Consequently, sensitive proxy authentication data may be exposed to third-party servers. Applications utilizing libsoup for HTTP communication are potentially affected.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.