CVE-2025-11021
Last modified
CVE-2025-11021 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-11021?
How severe is CVE-2025-11021?
How do I fix CVE-2025-11021?
Are you affected by CVE-2025-11021?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
