Skip to content
Critical Vulnerabilities in Fedora 43: Information Disclosure and Header Smuggling

Critical Vulnerabilities in Fedora 43: Information Disclosure and Header Smuggling

First seen 5 Jun 2026, 12:10 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 6, 2026 at 11:53 UTC
  • CVE-2026-5119 allows information disclosure via cleartext cookie transmission.
  • CVE-2026-7010 fixes a header smuggling vulnerability in perl-HTTP-Tiny.
  • Users are advised to update their systems using the dnf upgrade command.

Fedora 43 has reported two critical vulnerabilities affecting libsoup3 and perl-HTTP-Tiny. CVE-2026-5119, published on March 30, 2026, allows information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment. This vulnerability impacts users of libsoup3 in Fedora 43. CVE-2026-7010, published on May 11, 2026, addresses a header smuggling issue in perl-HTTP-Tiny, which can introduce security risks by allowing invalid characters in headers. Both vulnerabilities can be mitigated by applying the latest updates available through the dnf update program. Users are urged to upgrade to the patched versions to secure their systems against potential exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 97d ago How this analysis works

Timeline

2026-03-30
CVE-2026-5119 published
CVE-2026-5119 disclosed information disclosure via cleartext cookies in libsoup3.
Linuxsecurity
2026-05-11
CVE-2026-7010 published
CVE-2026-7010 published addressing header smuggling in perl-HTTP-Tiny.
Linuxsecurity
2026-05-19
CVE-2026-5119 patched
Fedora released an update to fix CVE-2026-5119 in libsoup3.
Linuxsecurity
2026-05-20
CVE-2026-7010 patched
An update was released for perl-HTTP-Tiny to address CVE-2026-7010.
Linuxsecurity

More articles in this cluster (99)

Following this threat?

Track Fedora and CVE-2025-66622 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed