ECHO-0bd2-8b5e-2b5a

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-0bd2-8b5e-2b5a.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-0bd2-8b5e-2b5a
Upstream
Withdrawn
2026-07-19T16:45:02Z
Published
2026-06-01T07:29:59Z
Modified
2026-09-15T03:33:43Z
Summary
SoupCache ignores the HTTP Vary header when reusing cached responses. The vulnerable path is only reachable when a client explicitly enables the optional on-disk SoupCache feature (soup_session_add_feature with SoupCache) AND acts as a shared/multi-user HTTP proxy — neither applies to Echo's use of libsoup3 as a client library. No upstream fix exists (a TODO in soup_cache_has_response(); issue #453 was closed as a duplicate of the still-open upstream issue #112). Debian rates it no-dsa, Minor. https://security-tracker.debian.org/tracker/CVE-2025-9901
Details
References

Affected packages

Echo / libsoup3

Package

Name
libsoup3
Purl
pkg:deb/echo/libsoup3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.6.6-1+e4

Database specific

source
"https://advisory.echohq.com/osv/ECHO-0bd2-8b5e-2b5a.json"