Libsoup: information disclosure may leads libsoup client sends authorization header to a different host when being redirected by a server (CVE-2025-46421) | HOL Guard CVE