CVE-2025-4035
Publication date 29 April 2025
Last updated 24 September 2025
Ubuntu priority
Cvss 3 Severity Score
Description
A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set cookies for domains it does not own, potentially leading to integrity issues such as session fixation.
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| libsoup3 | 25.10 questing | 
                              
                               
                                Vulnerable, fix deferred 
                                
                               
                             |      
                          
                            
                          
                        
                      
| 25.04 plucky | 
                              
                               
                                Vulnerable, fix deferred 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 24.04 LTS noble | 
                              
                               
                                Vulnerable, fix deferred 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 22.04 LTS jammy | 
                              
                               
                                Vulnerable, fix deferred 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 20.04 LTS focal | Not in release | |
| libsoup2.4 | 25.10 questing | 
                              
                               
                                Vulnerable, fix deferred 
                                
                               
                             |      
                          
                            
                          
                        
                      
| 25.04 plucky | 
                              
                               
                                Vulnerable, fix deferred 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 24.04 LTS noble | 
                              
                               
                                Vulnerable, fix deferred 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 22.04 LTS jammy | 
                              
                               
                                Vulnerable, fix deferred 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 20.04 LTS focal | 
                              
                               
                                Vulnerable, fix deferred 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 18.04 LTS bionic | 
                              
                               
                                Vulnerable, fix deferred 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 16.04 LTS xenial | 
                              
                               
                                Vulnerable, fix deferred 
                                
                               
                             |      
                          
                            
                          
                        
                      
Notes
Patch details
| Package | Patch details | 
|---|---|
| libsoup3 | 
Severity score breakdown
| Parameter | Value | 
|---|---|
| Base score | 
                      
                      
                         | 
                  
| Attack vector | Network | 
| Attack complexity | Low | 
| Privileges required | None | 
| User interaction | Required | 
| Scope | Unchanged | 
| Confidentiality | None | 
| Integrity impact | Low | 
| Availability impact | None | 
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |