← Vulnerability feed

Vulnerability record · CVE-2025-14523 · published 11 December 2025

CVE-2025-14523: HTTP request smuggling vulnerability

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

8.2 CVSS 3.1 High EPSS 0.54% · top 56.6% CWE-444 · HTTP request smuggling Deferred
8.2CVSS 3.1 base score
0.54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
0Affected product versions listed by NVD
21References
29 Jun 2026Last modified by NVD

Description

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

References

Track CVE-2025-14523 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2025-14523), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.