Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:0908 - Security Advisory
Issued:
2026-01-21
Updated:
2026-01-21

RHSA-2026:0908 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libsoup security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libsoup is now available for Red Hat Enterprise Linux 9.4 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libsoup packages provide an HTTP client and server library for GNOME.

Security Fix(es):

  • libsoup: libsoup: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (First- vs Last-Value Wins) (CVE-2025-14523)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.4 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64
  • Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le
  • Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x

Fixes

  • BZ - 2421349 - CVE-2025-14523 libsoup: libsoup: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (First- vs Last-Value Wins)

CVEs

  • CVE-2025-14523

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4

SRPM
libsoup-2.72.0-8.el9_4.8.src.rpm SHA-256: fddfada5a4c6b0b54cf1b0757d4ed83ec16f9bd78b59b1a7796043ed01ef5a54
x86_64
libsoup-2.72.0-8.el9_4.8.i686.rpm SHA-256: 9d6eb7721a51ce47c9d608b7c9d24bcaaf2f37eb67880389fa5bed021e64fe18
libsoup-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: 7c498f0abf755ad260b5a004fe50e2f98f6f2a2316b974c2caa1634a96dcff1d
libsoup-debuginfo-2.72.0-8.el9_4.8.i686.rpm SHA-256: bf3c111e7be2d15d07aa98e2aee1c0b2c8272666bc6078287abdc862bf43ad43
libsoup-debuginfo-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: cfdb92ef7f5c3d60de513fd7f6ff03fb352ffbb28d6a566bb517d7dc90e2f8c6
libsoup-debugsource-2.72.0-8.el9_4.8.i686.rpm SHA-256: fefbeb799717c38552b64375a2a9527072a0d54a27f38d6dc1020ca2f9a0c626
libsoup-debugsource-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: 985180c78cc02519b745aac59a20877c762b155caf598b15b43824d8c01e2474
libsoup-devel-2.72.0-8.el9_4.8.i686.rpm SHA-256: 437b125796a36c2226f50fc06a8029ef3fea14a761dff3ca6b916c1ebdee6bbc
libsoup-devel-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: eb4fbd57827e0ffc4bcf93e4931cfe638f36827cfdafc3e631bb5aea4770b8f4

Red Hat Enterprise Linux Server - AUS 9.4

SRPM
libsoup-2.72.0-8.el9_4.8.src.rpm SHA-256: fddfada5a4c6b0b54cf1b0757d4ed83ec16f9bd78b59b1a7796043ed01ef5a54
x86_64
libsoup-2.72.0-8.el9_4.8.i686.rpm SHA-256: 9d6eb7721a51ce47c9d608b7c9d24bcaaf2f37eb67880389fa5bed021e64fe18
libsoup-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: 7c498f0abf755ad260b5a004fe50e2f98f6f2a2316b974c2caa1634a96dcff1d
libsoup-debuginfo-2.72.0-8.el9_4.8.i686.rpm SHA-256: bf3c111e7be2d15d07aa98e2aee1c0b2c8272666bc6078287abdc862bf43ad43
libsoup-debuginfo-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: cfdb92ef7f5c3d60de513fd7f6ff03fb352ffbb28d6a566bb517d7dc90e2f8c6
libsoup-debugsource-2.72.0-8.el9_4.8.i686.rpm SHA-256: fefbeb799717c38552b64375a2a9527072a0d54a27f38d6dc1020ca2f9a0c626
libsoup-debugsource-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: 985180c78cc02519b745aac59a20877c762b155caf598b15b43824d8c01e2474
libsoup-devel-2.72.0-8.el9_4.8.i686.rpm SHA-256: 437b125796a36c2226f50fc06a8029ef3fea14a761dff3ca6b916c1ebdee6bbc
libsoup-devel-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: eb4fbd57827e0ffc4bcf93e4931cfe638f36827cfdafc3e631bb5aea4770b8f4

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4

SRPM
libsoup-2.72.0-8.el9_4.8.src.rpm SHA-256: fddfada5a4c6b0b54cf1b0757d4ed83ec16f9bd78b59b1a7796043ed01ef5a54
s390x
libsoup-2.72.0-8.el9_4.8.s390x.rpm SHA-256: 9ffd7b118b5ac336e61f34a8d1b08f3904d126953c58c834200d78bfbae4b922
libsoup-debuginfo-2.72.0-8.el9_4.8.s390x.rpm SHA-256: 1811c96d447a7c05022f2d2a8c9c799914670575454eb6f667cf70941bc0f563
libsoup-debugsource-2.72.0-8.el9_4.8.s390x.rpm SHA-256: 40b806b715d9b762636e34602998c51980e6d7f13ab8b02e8bae086ddf40b5fb
libsoup-devel-2.72.0-8.el9_4.8.s390x.rpm SHA-256: 05a28756368c061ca3163b8dbd807b230a4850779111835512dca6779f4c2da9

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4

SRPM
libsoup-2.72.0-8.el9_4.8.src.rpm SHA-256: fddfada5a4c6b0b54cf1b0757d4ed83ec16f9bd78b59b1a7796043ed01ef5a54
ppc64le
libsoup-2.72.0-8.el9_4.8.ppc64le.rpm SHA-256: fa44e3fdebe5725c8d75b409f79dd5719146ccc08bb363aebcb73cc6a0da2ee9
libsoup-debuginfo-2.72.0-8.el9_4.8.ppc64le.rpm SHA-256: c042ced99a41697dd4cd582253bf868f41f95653c3ba04790452b921a758a8ba
libsoup-debugsource-2.72.0-8.el9_4.8.ppc64le.rpm SHA-256: 5a717e2c4d32c8cc34f1ecd3bc109d9ff2cdb82fd9e1168021accc4dff751a4b
libsoup-devel-2.72.0-8.el9_4.8.ppc64le.rpm SHA-256: b560e0092efe8c7ac725db5acf02fea26e705ab2c2e8cb33d024811b7ce1f60a

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4

SRPM
libsoup-2.72.0-8.el9_4.8.src.rpm SHA-256: fddfada5a4c6b0b54cf1b0757d4ed83ec16f9bd78b59b1a7796043ed01ef5a54
aarch64
libsoup-2.72.0-8.el9_4.8.aarch64.rpm SHA-256: 3608fcb34938f74b0dbcc923fb570c30c3c56c8dc74010373c76c21df929a44d
libsoup-debuginfo-2.72.0-8.el9_4.8.aarch64.rpm SHA-256: 0e4bffb9f0a652d0002474c9ba3ab0cf340c16c788a0f6ace60d3877b5a0199b
libsoup-debugsource-2.72.0-8.el9_4.8.aarch64.rpm SHA-256: 474e552c1d81e56e0bc5cb8ca9658a7574accda87be3398788cb290b2ad630b5
libsoup-devel-2.72.0-8.el9_4.8.aarch64.rpm SHA-256: 64d38a185d6b4731c8e1a548d8d7fe811297c70202f4df1a599ef65a56f7e5b6

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4

SRPM
libsoup-2.72.0-8.el9_4.8.src.rpm SHA-256: fddfada5a4c6b0b54cf1b0757d4ed83ec16f9bd78b59b1a7796043ed01ef5a54
ppc64le
libsoup-2.72.0-8.el9_4.8.ppc64le.rpm SHA-256: fa44e3fdebe5725c8d75b409f79dd5719146ccc08bb363aebcb73cc6a0da2ee9
libsoup-debuginfo-2.72.0-8.el9_4.8.ppc64le.rpm SHA-256: c042ced99a41697dd4cd582253bf868f41f95653c3ba04790452b921a758a8ba
libsoup-debugsource-2.72.0-8.el9_4.8.ppc64le.rpm SHA-256: 5a717e2c4d32c8cc34f1ecd3bc109d9ff2cdb82fd9e1168021accc4dff751a4b
libsoup-devel-2.72.0-8.el9_4.8.ppc64le.rpm SHA-256: b560e0092efe8c7ac725db5acf02fea26e705ab2c2e8cb33d024811b7ce1f60a

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4

SRPM
libsoup-2.72.0-8.el9_4.8.src.rpm SHA-256: fddfada5a4c6b0b54cf1b0757d4ed83ec16f9bd78b59b1a7796043ed01ef5a54
x86_64
libsoup-2.72.0-8.el9_4.8.i686.rpm SHA-256: 9d6eb7721a51ce47c9d608b7c9d24bcaaf2f37eb67880389fa5bed021e64fe18
libsoup-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: 7c498f0abf755ad260b5a004fe50e2f98f6f2a2316b974c2caa1634a96dcff1d
libsoup-debuginfo-2.72.0-8.el9_4.8.i686.rpm SHA-256: bf3c111e7be2d15d07aa98e2aee1c0b2c8272666bc6078287abdc862bf43ad43
libsoup-debuginfo-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: cfdb92ef7f5c3d60de513fd7f6ff03fb352ffbb28d6a566bb517d7dc90e2f8c6
libsoup-debugsource-2.72.0-8.el9_4.8.i686.rpm SHA-256: fefbeb799717c38552b64375a2a9527072a0d54a27f38d6dc1020ca2f9a0c626
libsoup-debugsource-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: 985180c78cc02519b745aac59a20877c762b155caf598b15b43824d8c01e2474
libsoup-devel-2.72.0-8.el9_4.8.i686.rpm SHA-256: 437b125796a36c2226f50fc06a8029ef3fea14a761dff3ca6b916c1ebdee6bbc
libsoup-devel-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: eb4fbd57827e0ffc4bcf93e4931cfe638f36827cfdafc3e631bb5aea4770b8f4

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4

SRPM
libsoup-2.72.0-8.el9_4.8.src.rpm SHA-256: fddfada5a4c6b0b54cf1b0757d4ed83ec16f9bd78b59b1a7796043ed01ef5a54
aarch64
libsoup-2.72.0-8.el9_4.8.aarch64.rpm SHA-256: 3608fcb34938f74b0dbcc923fb570c30c3c56c8dc74010373c76c21df929a44d
libsoup-debuginfo-2.72.0-8.el9_4.8.aarch64.rpm SHA-256: 0e4bffb9f0a652d0002474c9ba3ab0cf340c16c788a0f6ace60d3877b5a0199b
libsoup-debugsource-2.72.0-8.el9_4.8.aarch64.rpm SHA-256: 474e552c1d81e56e0bc5cb8ca9658a7574accda87be3398788cb290b2ad630b5
libsoup-devel-2.72.0-8.el9_4.8.aarch64.rpm SHA-256: 64d38a185d6b4731c8e1a548d8d7fe811297c70202f4df1a599ef65a56f7e5b6

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4

SRPM
libsoup-2.72.0-8.el9_4.8.src.rpm SHA-256: fddfada5a4c6b0b54cf1b0757d4ed83ec16f9bd78b59b1a7796043ed01ef5a54
s390x
libsoup-2.72.0-8.el9_4.8.s390x.rpm SHA-256: 9ffd7b118b5ac336e61f34a8d1b08f3904d126953c58c834200d78bfbae4b922
libsoup-debuginfo-2.72.0-8.el9_4.8.s390x.rpm SHA-256: 1811c96d447a7c05022f2d2a8c9c799914670575454eb6f667cf70941bc0f563
libsoup-debugsource-2.72.0-8.el9_4.8.s390x.rpm SHA-256: 40b806b715d9b762636e34602998c51980e6d7f13ab8b02e8bae086ddf40b5fb
libsoup-devel-2.72.0-8.el9_4.8.s390x.rpm SHA-256: 05a28756368c061ca3163b8dbd807b230a4850779111835512dca6779f4c2da9

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4

SRPM
libsoup-2.72.0-8.el9_4.8.src.rpm SHA-256: fddfada5a4c6b0b54cf1b0757d4ed83ec16f9bd78b59b1a7796043ed01ef5a54
x86_64
libsoup-2.72.0-8.el9_4.8.i686.rpm SHA-256: 9d6eb7721a51ce47c9d608b7c9d24bcaaf2f37eb67880389fa5bed021e64fe18
libsoup-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: 7c498f0abf755ad260b5a004fe50e2f98f6f2a2316b974c2caa1634a96dcff1d
libsoup-debuginfo-2.72.0-8.el9_4.8.i686.rpm SHA-256: bf3c111e7be2d15d07aa98e2aee1c0b2c8272666bc6078287abdc862bf43ad43
libsoup-debuginfo-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: cfdb92ef7f5c3d60de513fd7f6ff03fb352ffbb28d6a566bb517d7dc90e2f8c6
libsoup-debugsource-2.72.0-8.el9_4.8.i686.rpm SHA-256: fefbeb799717c38552b64375a2a9527072a0d54a27f38d6dc1020ca2f9a0c626
libsoup-debugsource-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: 985180c78cc02519b745aac59a20877c762b155caf598b15b43824d8c01e2474
libsoup-devel-2.72.0-8.el9_4.8.i686.rpm SHA-256: 437b125796a36c2226f50fc06a8029ef3fea14a761dff3ca6b916c1ebdee6bbc
libsoup-devel-2.72.0-8.el9_4.8.x86_64.rpm SHA-256: eb4fbd57827e0ffc4bcf93e4931cfe638f36827cfdafc3e631bb5aea4770b8f4

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4

SRPM
libsoup-2.72.0-8.el9_4.8.src.rpm SHA-256: fddfada5a4c6b0b54cf1b0757d4ed83ec16f9bd78b59b1a7796043ed01ef5a54
aarch64
libsoup-2.72.0-8.el9_4.8.aarch64.rpm SHA-256: 3608fcb34938f74b0dbcc923fb570c30c3c56c8dc74010373c76c21df929a44d
libsoup-debuginfo-2.72.0-8.el9_4.8.aarch64.rpm SHA-256: 0e4bffb9f0a652d0002474c9ba3ab0cf340c16c788a0f6ace60d3877b5a0199b
libsoup-debugsource-2.72.0-8.el9_4.8.aarch64.rpm SHA-256: 474e552c1d81e56e0bc5cb8ca9658a7574accda87be3398788cb290b2ad630b5
libsoup-devel-2.72.0-8.el9_4.8.aarch64.rpm SHA-256: 64d38a185d6b4731c8e1a548d8d7fe811297c70202f4df1a599ef65a56f7e5b6

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4

SRPM
libsoup-2.72.0-8.el9_4.8.src.rpm SHA-256: fddfada5a4c6b0b54cf1b0757d4ed83ec16f9bd78b59b1a7796043ed01ef5a54
ppc64le
libsoup-2.72.0-8.el9_4.8.ppc64le.rpm SHA-256: fa44e3fdebe5725c8d75b409f79dd5719146ccc08bb363aebcb73cc6a0da2ee9
libsoup-debuginfo-2.72.0-8.el9_4.8.ppc64le.rpm SHA-256: c042ced99a41697dd4cd582253bf868f41f95653c3ba04790452b921a758a8ba
libsoup-debugsource-2.72.0-8.el9_4.8.ppc64le.rpm SHA-256: 5a717e2c4d32c8cc34f1ecd3bc109d9ff2cdb82fd9e1168021accc4dff751a4b
libsoup-devel-2.72.0-8.el9_4.8.ppc64le.rpm SHA-256: b560e0092efe8c7ac725db5acf02fea26e705ab2c2e8cb33d024811b7ce1f60a

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4

SRPM
libsoup-2.72.0-8.el9_4.8.src.rpm SHA-256: fddfada5a4c6b0b54cf1b0757d4ed83ec16f9bd78b59b1a7796043ed01ef5a54
s390x
libsoup-2.72.0-8.el9_4.8.s390x.rpm SHA-256: 9ffd7b118b5ac336e61f34a8d1b08f3904d126953c58c834200d78bfbae4b922
libsoup-debuginfo-2.72.0-8.el9_4.8.s390x.rpm SHA-256: 1811c96d447a7c05022f2d2a8c9c799914670575454eb6f667cf70941bc0f563
libsoup-debugsource-2.72.0-8.el9_4.8.s390x.rpm SHA-256: 40b806b715d9b762636e34602998c51980e6d7f13ab8b02e8bae086ddf40b5fb
libsoup-devel-2.72.0-8.el9_4.8.s390x.rpm SHA-256: 05a28756368c061ca3163b8dbd807b230a4850779111835512dca6779f4c2da9

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility