CVE-2018-12910: Critical severity Gnome libsoup vulnerability
Last updated 25 August 2025
Other sources
libsoup through version 2.63.2 is vulnerable to a crash in the soupcookiejar.c:getcookies() when handling empty hostnames.
Upstream Patch:
https://gitlab.gnome.org/GNOME/libsoup/commit/db2b0d5809d5f8226d47312b40992cadbcde439f
— Red Hat
The getcookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-12910?
CVE-2018-12910 is a vulnerability in libsoup 2.63.2 that allows attackers to have an unspecified impact via an empty hostname in the get_cookies function.
What is the severity of CVE-2018-12910?
CVE-2018-12910 has a severity level of critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2018-12910?
CVE-2018-12910 affects libsoup 2.63.2, 2.62.2-2, 2.52.2-1ubuntu0.3, 2.60.1-1ubuntu0.1, 2.62.1-1ubuntu0.1, 2.44.2-1ubuntu2.3, 2.64.2-2, 2.72.0-2, and 2.74.3-1.
How can I fix CVE-2018-12910?
To fix CVE-2018-12910, upgrade to a version of libsoup that is not affected by the vulnerability, such as 2.64.2-2, 2.72.0-2, or 2.74.3-1.
Where can I find more information about CVE-2018-12910?
You can find more information about CVE-2018-12910 at the following references: [link1](https://gitlab.gnome.org/GNOME/libsoup/commit/db2b0d5809d5f8226d47312b40992cadbcde439f), [link2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SBREWZ3EEDYWG6PCLWL2EJ24ME5ZFAX6/), [link3](https://www.debian.org/security/2018/dsa-4241).