{"id":"ECHO-0bd2-8b5e-2b5a","summary":"SoupCache ignores the HTTP Vary header when reusing cached responses. The\nvulnerable path is only reachable when a client explicitly enables the optional\non-disk SoupCache feature (soup_session_add_feature with SoupCache) AND acts as a\nshared/multi-user HTTP proxy — neither applies to Echo's use of libsoup3 as a\nclient library. No upstream fix exists (a TODO in soup_cache_has_response();\nissue #453 was closed as a duplicate of the still-open upstream issue #112).\nDebian rates it no-dsa, Minor.\nhttps://security-tracker.debian.org/tracker/CVE-2025-9901\n","modified":"2026-09-15T03:33:43.804178912Z","published":"2026-06-01T07:29:59.788Z","withdrawn":"2026-07-19T16:45:02.845Z","upstream":["CVE-2025-9901"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2025-9901"}],"affected":[{"package":{"name":"libsoup3","ecosystem":"Echo","purl":"pkg:deb/echo/libsoup3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.6-1+e4"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-0bd2-8b5e-2b5a.json"}}],"schema_version":"1.9.0"}