Linuxsecurity
Critical Vulnerabilities in Fedora 43: Information Disclosure and Header Smuggling
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Fedora 43 has reported two critical vulnerabilities affecting libsoup3 and perl-HTTP-Tiny. CVE-2026-5119, published on March 30, 2026, allows information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment. This vulnerability impacts users of libsoup3 in Fedora 43. CVE-2026-7010, published on May 11, 2026, addresses a header smuggling issue in perl-HTTP-Tiny, which can introduce security risks by allowing invalid characters in headers. Both vulnerabilities can be mitigated by applying the latest updates available through the dnf update program. Users are urged to upgrade to the patched versions to secure their systems against potential exploitation.
Key Points: • CVE-2026-5119 allows information disclosure via cleartext cookie transmission. • CVE-2026-7010 fixes a header smuggling vulnerability in perl-HTTP-Tiny. • Users are advised to update their systems using the dnf upgrade command.