---
id: CVE-2025-4035
title: A flaw was found in libsoup
summary: >-
  A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly
  allow cookies to be set for public suffix domains if the domain contains at
  least two components and includes an uppercase character. This bypasses public
  suf…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-178
published: '2025-04-29'
updated: '2026-06-26'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-4035'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:8128'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-4035'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2362651'
    label: secalert@redhat.com
  - url: 'https://gitlab.gnome.org/GNOME/libsoup/-/issues/443'
    label: secalert@redhat.com
tags:
  - nvd
epss: 0.0042
epssPercentile: 0.35993
ingestedAt: '2026-06-26T16:43:13.602Z'
---

## Overview

A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set cookies for domains it does not own, potentially leading to integrity issues such as session fixation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
