Gnome

Libsoup

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.23%
  • Veröffentlicht 24.07.2026 23:16:52
  • Zuletzt bearbeitet 24.08.2026 16:44:01

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the des...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 24.07.2026 23:16:52
  • Zuletzt bearbeitet 24.08.2026 16:44:22

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. W...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 24.07.2026 23:16:51
  • Zuletzt bearbeitet 24.08.2026 16:44:56

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multi...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 21.07.2026 19:17:09
  • Zuletzt bearbeitet 24.08.2026 16:45:12

A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated, leading to a heap buffer over-...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 22.06.2026 13:55:06
  • Zuletzt bearbeitet 08.07.2026 15:10:43

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 23.04.2026 21:51:23
  • Zuletzt bearbeitet 04.05.2026 18:28:46

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or confl...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 30.03.2026 05:35:57
  • Zuletzt bearbeitet 09.06.2026 10:16:44

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can ...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 26.03.2026 19:31:34
  • Zuletzt bearbeitet 21.04.2026 15:48:48

A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake co...

  • EPSS 0.42%
  • Veröffentlicht 19.03.2026 14:20:27
  • Zuletzt bearbeitet 28.04.2026 21:29:20

A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially access sensitive information or cause an application l...

Exploit
  • EPSS 0.83%
  • Veröffentlicht 17.03.2026 11:14:21
  • Zuletzt bearbeitet 19.05.2026 22:16:38

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2 requests that cause a...