CVE-2025-46421: Red Hat Enterprise Linux 10
Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.
A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 0:3.6.5-3.el10_0 (fixed in 0:3.6.5-3.el10_0)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8: before 0:2.62.3-8.el8_10 (fixed in 0:2.62.3-8.el8_10)
- Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support: before 0:2.62.3-1.el8_2.4 (fixed in 0:2.62.3-1.el8_2.4)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:2.62.3-2.el8_4.4 (fixed in 0:2.62.3-2.el8_4.4)
- Red Hat Red Hat Enterprise Linux 8.4 Telecommunications Update Service: before 0:2.62.3-2.el8_4.4 (fixed in 0:2.62.3-2.el8_4.4)
- Red Hat Red Hat Enterprise Linux 8.4 Update Services For SAP Solutions: before 0:2.62.3-2.el8_4.4 (fixed in 0:2.62.3-2.el8_4.4)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:2.62.3-2.el8_6.4 (fixed in 0:2.62.3-2.el8_6.4)
- Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service: before 0:2.62.3-2.el8_6.4 (fixed in 0:2.62.3-2.el8_6.4)
- Red Hat Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions: before 0:2.62.3-2.el8_6.4 (fixed in 0:2.62.3-2.el8_6.4)
- Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support: before 0:2.62.3-3.el8_8.4 (fixed in 0:2.62.3-3.el8_8.4)
- Red Hat Red Hat Enterprise Linux 9: before 0:2.72.0-10.el9_6.1 (fixed in 0:2.72.0-10.el9_6.1)
- Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 0:2.72.0-8.el9_0.4 (fixed in 0:2.72.0-8.el9_0.4)
- Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 0:2.72.0-8.el9_2.4 (fixed in 0:2.72.0-8.el9_2.4)
- Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 0:2.72.0-8.el9_4.4 (fixed in 0:2.72.0-8.el9_4.4)
Published 2025-04-24. Last modified 2026-06-30.