Search CVE reports


Toggle filters

1 – 10 of 44 results


CVE-2026-1801

Medium priority
Needs evaluation

A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsoup2.4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libsoup3 Needs evaluation Needs evaluation
Show less packages

CVE-2026-1761

Medium priority
Needs evaluation

A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsoup2.4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libsoup3 Needs evaluation Needs evaluation
Show less packages

CVE-2026-1760

Medium priority
Needs evaluation

A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding: chunked and Connection: keep-alive headers. A remote, unauthenticated...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsoup2.4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libsoup3 Needs evaluation Needs evaluation
Show less packages

CVE-2026-1539

Medium priority
Vulnerable

A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsoup2.4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libsoup3 Vulnerable Vulnerable
Show less packages

CVE-2026-1536

Medium priority
Vulnerable

A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsoup2.4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libsoup3 Vulnerable Vulnerable
Show less packages

CVE-2026-1467

Medium priority
Vulnerable

A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsoup2.4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libsoup3 Vulnerable Vulnerable
Show less packages

CVE-2026-0716

Medium priority
Vulnerable

A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsoup2.4 Vulnerable Vulnerable Vulnerable Vulnerable
libsoup3 Vulnerable Vulnerable
Show less packages

CVE-2026-0719

Medium priority
Vulnerable

A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsoup2.4 Vulnerable Vulnerable Vulnerable Vulnerable
libsoup3 Vulnerable Vulnerable
Show less packages

CVE-2025-14523

Medium priority
Vulnerable

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsoup2.4 Vulnerable Vulnerable Vulnerable Vulnerable
libsoup3 Vulnerable Vulnerable
Show less packages

CVE-2025-12105

Medium priority
Fixed

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libsoup2.4 Not affected Not affected Not affected Not affected
libsoup3 Fixed Fixed
Show less packages