Libsoup: libsoup: denial of service via use-after-free in http/2 server
Published Mar 17, 2026
7.5
HIGHCVSS 3.1
EPSS 1.34%
Description
A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2 requests that cause authentication failures. This can lead to the application attempting to access memory that has already been freed, potentially causing application instability or crashes, resulting in a Denial of Service (DoS).
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 6 | affected |
|
- n/a
- 6.0
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 10
libsoup3-0:3.6.5-3.el10_1.11
Fixed · RHSA-2026:15968
Red Hat Enterprise Linux 10
libsoup3-0:3.6.5-3.el10_2.11
Fixed · RHSA-2026:19143
Red Hat Enterprise Linux 10.0 Extended Update Support
libsoup3-0:3.6.5-3.el10_0.15
Fixed · RHSA-2026:17482
Red Hat Enterprise Linux 6
libsoup
Will not fix
Red Hat Enterprise Linux 7
libsoup
Not affected
Red Hat Enterprise Linux 8
libsoup
Not affected
Red Hat Enterprise Linux 9
libsoup
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | libsoup3-0:3.6.5-3.el10_1.11 | Fixed | RHSA-2026:15968 |
| Red Hat Enterprise Linux 10 | libsoup3-0:3.6.5-3.el10_2.11 | Fixed | RHSA-2026:19143 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | libsoup3-0:3.6.5-3.el10_0.15 | Fixed | RHSA-2026:17482 |
| Red Hat Enterprise Linux 6 | libsoup | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | libsoup | Not affected | n/a |
| Red Hat Enterprise Linux 8 | libsoup | Not affected | n/a |
| Red Hat Enterprise Linux 9 | libsoup | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
This MODERATE impact use-after-free flaw in libsoup's HTTP/2 server implementation affects applications that use libsoup to handle HTTP/2 server callbacks. An attacker can trigger this by sending HTTP/2 requests that cause authentication validation failures, potentially leading to application instability or crashes. Red Hat products are affected if they leverage libsoup as an HTTP/2 server and disconnect client connections during header processing.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (8)
- https://access.redhat.com/errata/RHSA-2026:15968 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:17482 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:19143 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-4271 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2448044 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/496 exploitIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-4271
- https://www.cve.org/CVERecord?id=CVE-2026-4271
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:15968 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:17482 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:19143 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-4271 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2448044 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://gitlab.gnome.org/GNOME/libsoup/-/issues/496 | exploitIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-4271 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-4271 |
Change history (0)
No recorded changes yet.