GNOME / Libsoup
30 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-66337 | Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_read_until() | MEDIUM | 6.5 | Jul 24, 2026 |
| CVE-2026-66338 | Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked() | HIGH | 7.2 | Jul 24, 2026 |
| CVE-2026-66339 | Libsoup: libsoup: proxy credentials leak to destination server via proxy-authorization header in connect tunnels | MEDIUM | 6.5 | Jul 24, 2026 |
| CVE-2026-12548 | Libsoup: heap out-of-bounds read in libsoup due to integer truncation | MEDIUM | 4.2 | Jul 21, 2026 |
| CVE-2026-12549 | Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver | MEDIUM | 4.8 | Jun 22, 2026 |
| CVE-2026-2708 | Libsoup: libsoup: http request smuggling via duplicate content-length headers | MEDIUM | 5.3 | Apr 23, 2026 |
| CVE-2026-5119 | Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment | HIGH | 8.2 | Mar 30, 2026 |
| CVE-2026-2436 | Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake | HIGH | 8.2 | Mar 26, 2026 |
| CVE-2026-2369 | Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources | CRITICAL | 9.1 | Mar 19, 2026 |
| CVE-2026-4271 | Libsoup: libsoup: denial of service via use-after-free in http/2 server | HIGH | 7.5 | Mar 17, 2026 |
| CVE-2026-3633 | Libsoup: libsoup: header and http request injection via crlf injection | MEDIUM | 6.5 | Mar 17, 2026 |
| CVE-2026-3632 | Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames | MEDIUM | 5.5 | Mar 17, 2026 |
| CVE-2026-3634 | Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header | MEDIUM | 6.5 | Mar 17, 2026 |
| CVE-2026-3099 | Libsoup: libsoup: authentication bypass via digest authentication replay attack | HIGH | 7.3 | Mar 12, 2026 |
| CVE-2026-2443 | Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure | MEDIUM | 5.3 | Feb 13, 2026 |
| CVE-2026-1801 | Libsoup: libsoup: http request smuggling via malformed chunk headers | MEDIUM | 6.5 | Feb 3, 2026 |
| CVE-2026-1539 | Libsoup: libsoup: credential leakage via http redirects | MEDIUM | 5.8 | Jan 28, 2026 |
| CVE-2026-1536 | Libsoup: libsoup: http header injection or response splitting via crlf injection in content-disposition header | MEDIUM | 5.8 | Jan 28, 2026 |
| CVE-2026-1467 | Libsoup: libsoup: http header injection via specially crafted urls when an http proxy is configured | MEDIUM | 5.8 | Jan 27, 2026 |
| CVE-2025-12105 | Libsoup: heap use-after-free in libsoup message queue handling during http/2 read completion | HIGH | 7.5 | Oct 23, 2025 |
| CVE-2025-2784 | Libsoup: heap buffer over-read in `skip_insignificant_space` when sniffing content | HIGH | 7.0 | Apr 3, 2025 |
| CVE-2024-52532 | libsoup: infinite loop while reading websocket data | HIGH | 7.5 | Nov 11, 2024 |
| CVE-2024-52531 | libsoup: buffer overflow via UTF-8 conversion in soup_header_parse_param_list_strict | CRITICAL | 9.0 | Nov 11, 2024 |
| CVE-2024-52530 | libsoup: HTTP request smuggling via stripping null bytes from the ends of header names | HIGH | 7.5 | Nov 11, 2024 |
| CVE-2019-17266 | libsoup: heap-based over-read in soup_ntlm_parse_challenge() in soup-auth-ntlm.c | CRITICAL | 9.8 | Oct 6, 2019 |
Showing 1 to 25 of 30 CVEs