CVE-2026-3634
- EPSS 0.18%
- Veröffentlicht 17.03.2026 09:44:19
- Zuletzt bearbeitet 19.03.2026 19:52:33
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. Th...
CVE-2026-3633
- EPSS 0.22%
- Veröffentlicht 17.03.2026 09:44:19
- Zuletzt bearbeitet 19.03.2026 19:53:34
A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Carriage Return Line Feed) inject...
CVE-2026-3632
- EPSS 0.21%
- Veröffentlicht 17.03.2026 09:44:19
- Zuletzt bearbeitet 19.03.2026 19:56:43
A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP headers. A remote attacker coul...
CVE-2026-3099
- EPSS 0.36%
- Veröffentlicht 12.03.2026 13:53:48
- Zuletzt bearbeitet 23.03.2026 14:02:25
A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute. This vulnerability allows a rem...
CVE-2026-2443
- EPSS 0.43%
- Veröffentlicht 13.02.2026 11:58:20
- Zuletzt bearbeitet 23.03.2026 20:16:25
A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a ...
CVE-2026-1801
- EPSS 0.38%
- Veröffentlicht 03.02.2026 20:12:21
- Zuletzt bearbeitet 26.03.2026 18:02:05
A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk headers, such as lone...
CVE-2026-1539
- EPSS 0.24%
- Veröffentlicht 28.01.2026 15:15:48
- Zuletzt bearbeitet 25.03.2026 14:08:59
A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization hea...
CVE-2026-1536
- EPSS 0.3%
- Veröffentlicht 28.01.2026 15:15:46
- Zuletzt bearbeitet 25.03.2026 14:14:38
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or ...
CVE-2026-1467
- EPSS 0.31%
- Veröffentlicht 27.01.2026 09:17:44
- Zuletzt bearbeitet 25.03.2026 14:20:18
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header....
CVE-2025-12105
- EPSS 0.43%
- Veröffentlicht 23.10.2025 09:14:14
- Zuletzt bearbeitet 30.06.2026 00:16:51
A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal mess...