CVE-2026-1801
- EPSS 0.03%
- Veröffentlicht 03.02.2026 20:12:21
- Zuletzt bearbeitet 26.03.2026 18:02:05
A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk headers, such as lone...
CVE-2026-1539
- EPSS 0.06%
- Veröffentlicht 28.01.2026 15:15:48
- Zuletzt bearbeitet 25.03.2026 14:08:59
A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization hea...
CVE-2026-1536
- EPSS 0.11%
- Veröffentlicht 28.01.2026 15:15:46
- Zuletzt bearbeitet 25.03.2026 14:14:38
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or ...
CVE-2026-1467
- EPSS 0.06%
- Veröffentlicht 27.01.2026 09:17:44
- Zuletzt bearbeitet 25.03.2026 14:20:18
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header....
CVE-2025-14512
- EPSS 0.07%
- Veröffentlicht 11.12.2025 07:16:00
- Zuletzt bearbeitet 11.05.2026 23:17:18
A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribu...
CVE-2025-14087
- EPSS 0.09%
- Veröffentlicht 10.12.2025 09:01:34
- Zuletzt bearbeitet 11.05.2026 23:17:17
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted i...
CVE-2025-9784
- EPSS 1.7%
- Veröffentlicht 02.09.2025 13:37:59
- Zuletzt bearbeitet 18.03.2026 16:16:24
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload b...
CVE-2025-8283
- EPSS 0.08%
- Veröffentlicht 28.07.2025 18:16:07
- Zuletzt bearbeitet 07.11.2025 22:15:39
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a co...
CVE-2025-7519
- EPSS 0.03%
- Veröffentlicht 14.07.2025 13:35:21
- Zuletzt bearbeitet 11.08.2025 19:20:21
A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. T...
CVE-2025-7424
- EPSS 0.37%
- Veröffentlicht 10.07.2025 14:05:41
- Zuletzt bearbeitet 27.04.2026 21:16:25
A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt m...