Cleartext Transmission of Sensitive Information has been reported in libsoup’s HTTP CONNECT handling. When establishing HTTPS tunnels via soup_session.c::tunnel_connect(), cookies (including potentially sensitive session cookies) are sent in cleartext within the initial HTTP CONNECT request to the configured proxy. A network-positioned attacker or malicious HTTP proxy can intercept or observe these cookies and leverage them for session hijacking or user impersonation.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:13978 https://access.redhat.com/errata/RHSA-2026:13978
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:14087 https://access.redhat.com/errata/RHSA-2026:14087
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:15968 https://access.redhat.com/errata/RHSA-2026:15968
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:17482 https://access.redhat.com/errata/RHSA-2026:17482
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19143 https://access.redhat.com/errata/RHSA-2026:19143
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19356 https://access.redhat.com/errata/RHSA-2026:19356
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:21686 https://access.redhat.com/errata/RHSA-2026:21686
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:22316 https://access.redhat.com/errata/RHSA-2026:22316
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:22317 https://access.redhat.com/errata/RHSA-2026:22317
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:22323 https://access.redhat.com/errata/RHSA-2026:22323
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:22710 https://access.redhat.com/errata/RHSA-2026:22710
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:22716 https://access.redhat.com/errata/RHSA-2026:22716