---
title: "CVE-2025-4035\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-4035?format=md
keywords: index, follow
---

# CVE-2025-4035

Publication date 29 April 2025

Last updated 11 March 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**4.3 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2025-4035?format=md#impact-score)

Toggle side navigation

## Description

A flaw was found in libsoup. When handling cookies, libsoup clients
mistakenly allow cookies to be set for public suffix domains if the domain
contains at least two components and includes an uppercase character. This
bypasses public suffix protections and could allow a malicious website to
set cookies for domains it does not own, potentially leading to integrity
issues such as session fixation.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2025-4035?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| libsoup2.4 | 26.04 LTS resolute | Vulnerable, fix deferred |
| 25.10 questing | Ignored end of life, was deferred [2026-03-11] |
| 25.04 plucky | Ignored end of life, was deferred [2026-03-11] |
| 24.10 oracular | Ignored end of life, was deferred [2025-07-28] |
| 24.04 LTS noble | Vulnerable, fix deferred |
| 22.04 LTS jammy | Vulnerable, fix deferred |
| 20.04 LTS focal | Vulnerable, fix deferred |
| 18.04 LTS bionic | Vulnerable, fix deferred |
| 16.04 LTS xenial | Vulnerable, fix deferred |
| libsoup3 | 26.04 LTS resolute | Vulnerable, fix deferred |
| 25.10 questing | Ignored end of life, was deferred [2026-03-11] |
| 25.04 plucky | Ignored end of life, was deferred [2026-03-11] |
| 24.10 oracular | Ignored end of life, was deferred [2025-09-23] |
| 24.04 LTS noble | Vulnerable, fix deferred |
| 22.04 LTS jammy | Vulnerable, fix deferred |
| 20.04 LTS focal | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2025-4035?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

may require epiphany-browser change, see:
https://gitlab.gnome.org/GNOME/epiphany/-/merge\_requests/1800
as of 2026-03-11, the proposed fix for this issue has not been
committed

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| libsoup3 | * Upstream:   <https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/448> |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

4.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | Low |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 4.3 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4035)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-4035)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-4035)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-4035)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-4035>
* <https://access.redhat.com/security/cve/CVE-2025-4035>
