CVE-2019-11070: WebKitGTK

Medium severity, CVSS 5.3. EPSS: 3.3% chance of exploitation in the next 30 days.

WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.

Affected products

  • WebKitGTK WebKitGTK: before 2.24.1 (fixed in 2.24.1)
  • Wpewebkit Wpe Webkit: before 2.24.1 (fixed in 2.24.1)

Published 2019-04-10. Last modified 2026-06-17.