<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 12:23:01 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-4035 — Libsoup: cookie domain validation bypass via uppercase characters in libsoup</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-4035</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set cookies for domains it does not own, potentially leading to integrity issues such as session fixation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set cookies for domains it does not own, potentially leading to integrity issues such as session fixation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-4035</guid>
    </item>
    <item>
      <title>RHSA-2025:8128 — Red Hat Security Advisory: libsoup3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:8128</link>
      <description>&lt;p&gt;libsoup: Cookie domain validation bypass via uppercase characters in libsoup libsoup: Integer Underflow in soup_multipart_new_from_message() Leading to Denial of Service in libsoup libsoup: Denial of Service attack to websocket server libsoup: Denial of service in server when client requests a large amount of  overlapping ranges with Range header&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libsoup: Cookie domain validation bypass via uppercase characters in libsoup libsoup: Integer Underflow in soup_multipart_new_from_message() Leading to Denial of Service in libsoup libsoup: Denial of Service attack to websocket server libsoup: Denial of service in server when client requests a large amount of  overlapping ranges with Range header&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:8128</guid>
    </item>
  </channel>
</rss>
