National Cyber Warfare Foundation (NCWF)

CVE-2025-4035


0 user ratings
2025-04-28 00:00:00
milo
CVEs

 - archive -- 

CVE-2025-4035

Date: 2025-04-28

CVE Link

A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set cookies for domains it does not own, potentially leading to integrity issues such as session fixation.



References:



Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
CVEs



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.