A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute. This vulnerability allows a remote attacker to capture a single valid authentication header and replay it repeatedly. Consequently, the attacker can bypass authentication and gain unauthorized access to protected resources, impersonating the legitimate user.
History

Thu, 12 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
References

Thu, 12 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute. This vulnerability allows a remote attacker to capture a single valid authentication header and replay it repeatedly. Consequently, the attacker can bypass authentication and gain unauthorized access to protected resources, impersonating the legitimate user.
Title libsoup: Libsoup: Authentication bypass via digest authentication replay attack Libsoup: libsoup: authentication bypass via digest authentication replay attack
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References

Wed, 25 Feb 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Libsoup
Libsoup libsoup
Vendors & Products Libsoup
Libsoup libsoup

Tue, 24 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title libsoup: Libsoup: Authentication bypass via digest authentication replay attack
Weaknesses CWE-323
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2026-03-12T13:53:48.848Z

Updated: 2026-03-12T17:44:43.631Z

Reserved: 2026-02-24T07:37:48.680Z

Link: CVE-2026-3099

cve-icon Vulnrichment

Updated: 2026-03-12T17:44:38.510Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-12T14:16:18.760

Modified: 2026-03-12T21:07:53.427

Link: CVE-2026-3099

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-02-24T01:01:00Z

Links: CVE-2026-3099 - Bugzilla