The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
{ "vanir_signatures": [ { "digest": { "function_hash": "163843925386063509471927901117875209963", "length": 1070.0 }, "id": "CVE-2018-12910-18e6feaf", "source": "https://gitlab.gnome.org/GNOME/libsoup@db2b0d5809d5f8226d47312b40992cadbcde439f", "signature_type": "Function", "signature_version": "v1", "target": { "file": "libsoup/soup-cookie-jar.c", "function": "get_cookies" }, "deprecated": false }, { "digest": { "threshold": 0.9, "line_hashes": [ "144556660119695155818398657603494205401", "40180601401922571943606266108522426556", "326934744825777591884259600856806841227", "284896594982118689249729973249601447671" ] }, "id": "CVE-2018-12910-dd26bbe0", "source": "https://gitlab.gnome.org/GNOME/libsoup@db2b0d5809d5f8226d47312b40992cadbcde439f", "signature_type": "Line", "signature_version": "v1", "target": { "file": "libsoup/soup-cookie-jar.c" }, "deprecated": false } ] }