Skip to content
Vulnerabilities in Ubuntu libsoup Lead to Session Hijacking Risks

Vulnerabilities in Ubuntu libsoup Lead to Session Hijacking Risks

First seen 10 Jul 2026, 06:55 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 14:16 UTC
  • •Two critical vulnerabilities in libsoup affect multiple Ubuntu LTS versions.
  • •CVE-2026-2369 could lead to information disclosure or denial of service.
  • •CVE-2026-5119 poses a risk of session hijacking via HTTP proxies.

Two vulnerabilities were discovered in the libsoup library affecting multiple Ubuntu LTS versions, including 18.04, 20.04, 22.04, 24.04, 25.10, and 26.04. The first vulnerability (CVE-2026-2369) allows attackers to trigger a buffer over-read due to improper handling of zero-length resources, potentially leading to information disclosure or denial of service. The second vulnerability (CVE-2026-5119) enables session hijacking by improperly protecting sensitive cookies during HTTPS tunnel establishment through HTTP proxies. Both vulnerabilities were published in March 2026, with patches available shortly after. Users are advised to update their systems to mitigate these risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-03-19
CVE-2026-2369 published
Vulnerability disclosed affecting multiple Ubuntu LTS versions, allowing buffer over-read.
Linuxsecurity
2026-03-30
CVE-2026-5119 published
Vulnerability disclosed allowing session hijacking through improper cookie protection.
Linuxsecurity
2026-07-09
Patches released for libsoup
Ubuntu released updates to fix the vulnerabilities in affected LTS versions.
Ubuntu

More articles in this cluster (6)

Following this threat?

Track CVE-2026-2369 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which Ubuntu versions are affected?
The vulnerabilities affect Ubuntu 18.04, 20.04, 22.04, 24.04, 25.10, and 26.04 LTS.
What are the risks associated with these vulnerabilities?
CVE-2026-2369 may lead to information disclosure or denial of service, while CVE-2026-5119 allows for session hijacking.
How can I protect my system?
Update your Ubuntu system to the latest package versions provided in the security notices.