When handling cookies, libsoup clients improperly validate domain names containing uppercase characters, allowing malicious websites to set cookies for public suffix domains and bypass expected isolation boundaries.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:8128 https://access.redhat.com/errata/RHSA-2025:8128