---
id: CVE-2025-11021
title: >-
  A flaw was found in the cookie date handling logic of the libsoup HTTP
  library, widely used by GNOME and other applications for web communication
summary: >-
  A flaw was found in the cookie date handling logic of the libsoup HTTP
  library, widely used by GNOME and other applications for web communication.
  When processing cookies with specially crafted expiration dates, the library
  may perform a…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-125
published: '2025-09-26'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11021'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:18183'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:19713'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:19714'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:20959'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:21032'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:21655'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:21656'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:21657'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:21664'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:21665'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:21666'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:21772'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:22013'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-11021'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2399627'
    label: secalert@redhat.com
  - url: 'https://gitlab.gnome.org/GNOME/libsoup/-/issues/459'
    label: secalert@redhat.com
tags:
  - nvd
epss: 0.00636
epssPercentile: 0.48294
ingestedAt: '2026-06-29T13:24:34.583Z'
---

## Overview

A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
