Linuxsecurity Vulnerabilities in Ubuntu libsoup Lead to Session Hijacking Risks
Article Content
- •Two critical vulnerabilities in libsoup affect multiple Ubuntu LTS versions.
- •CVE-2026-2369 could lead to information disclosure or denial of service.
- •CVE-2026-5119 poses a risk of session hijacking via HTTP proxies.
Two vulnerabilities were discovered in the libsoup library affecting multiple Ubuntu LTS versions, including 18.04, 20.04, 22.04, 24.04, 25.10, and 26.04. The first vulnerability (CVE-2026-2369) allows attackers to trigger a buffer over-read due to improper handling of zero-length resources, potentially leading to information disclosure or denial of service. The second vulnerability (CVE-2026-5119) enables session hijacking by improperly protecting sensitive cookies during HTTPS tunnel establishment through HTTP proxies. Both vulnerabilities were published in March 2026, with patches available shortly after. Users are advised to update their systems to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track CVE-2026-2369 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which Ubuntu versions are affected?
What are the risks associated with these vulnerabilities?
How can I protect my system?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…