Linuxsecurity Critical Vulnerabilities in Fedora 43: Information Disclosure and Header Smuggling
Article Content
- •CVE-2026-5119 allows information disclosure via cleartext cookie transmission.
- •CVE-2026-7010 fixes a header smuggling vulnerability in perl-HTTP-Tiny.
- •Users are advised to update their systems using the dnf upgrade command.
Fedora 43 has reported two critical vulnerabilities affecting libsoup3 and perl-HTTP-Tiny. CVE-2026-5119, published on March 30, 2026, allows information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment. This vulnerability impacts users of libsoup3 in Fedora 43. CVE-2026-7010, published on May 11, 2026, addresses a header smuggling issue in perl-HTTP-Tiny, which can introduce security risks by allowing invalid characters in headers. Both vulnerabilities can be mitigated by applying the latest updates available through the dnf update program. Users are urged to upgrade to the patched versions to secure their systems against potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (99)
Following this threat?
Track Fedora and CVE-2025-66622 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…