Gnome
Gnome Libsoup: vulnerabilidades y CVE
Gnome Libsoup tiene 45 vulnerabilidades publicadas, 26 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE45
Últimos 12 meses26
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85534 | Media (5.9) | 0.32% | — | 4 sept 2026 | A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can… |
| CVE-2026-85197 | Alta (7.6) | 0.27% | — | 4 sept 2026 | A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application… |
| CVE-2026-77680 | Media (5.3) | 0.34% | — | 25 ago 2026 | An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed memory amplification when a client repeated the same range many times… |
| CVE-2026-66339 | Media (6.5) | 0.25% | — | 24 jul 2026 | A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the… |
| CVE-2026-66338 | Alta (7.2) | 0.28% | — | 24 jul 2026 | A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and… |
| CVE-2026-66337 | Media (6.5) | 0.38% | — | 24 jul 2026 | A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit… |
| CVE-2026-12548 | Media (4.2) | 0.25% | — | 21 jul 2026 | A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated,… |
| CVE-2026-15712 | Media (5.9) | 0.50% | — | 14 jul 2026 | A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the library processes an HTTP/2 GOAWAY frame, it improperly handles the… |
| CVE-2026-12478 | Media (4.8) | 0.24% | — | 14 jul 2026 | The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a… |
| CVE-2026-12549 | Media (4.8) | 0.36% | — | 22 jun 2026 | The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the… |
| CVE-2026-6324 | Media (4.8) | 0.51% | — | 29 may 2026 | A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` function by sending a malicious HTTP request. This vulnerability occurs… |
| CVE-2026-2708 | Media (5.3) | 0.40% | — | 23 abr 2026 | A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without… |
| CVE-2026-5119 | Alta (8.2) | 0.33% | — | 30 mar 2026 | A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker… |
| CVE-2026-2436 | Alta (8.2) | 0.45% | — | 26 mar 2026 | A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is… |
| CVE-2026-2369 | Crítica (9.1) | 0.42% | — | 19 mar 2026 | A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially access sensitive… |
| CVE-2026-4271 | Alta (7.5) | 1.3% | — | 17 mar 2026 | A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially… |
| CVE-2026-3634 | Media (6.5) | 0.31% | — | 17 mar 2026 | A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the… |
| CVE-2026-3633 | Media (6.5) | 0.37% | — | 17 mar 2026 | A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF… |
| CVE-2026-3632 | Media (5.5) | 0.35% | — | 17 mar 2026 | A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP… |
| CVE-2026-3099 | Alta (7.3) | 0.48% | — | 12 mar 2026 | A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute.… |
| CVE-2026-2443 | Media (5.3) | 0.45% | — | 13 feb 2026 | A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build… |
| CVE-2026-1801 | Media (6.5) | 0.40% | — | 3 feb 2026 | A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts… |
| CVE-2026-1539 | Media (5.8) | 0.28% | — | 28 ene 2026 | A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not… |
| CVE-2026-1536 | Media (5.3) | 0.35% | — | 28 ene 2026 | A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted… |
| CVE-2026-1467 | Media (5.3) | 0.37% | — | 27 ene 2026 | A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input… |
| CVE-2026-0719 | Alta (8.6) | 0.62% | — | 8 ene 2026 | A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size… |
| CVE-2025-11021 | Alta (7.5) | 0.64% | — | 26 sept 2025 | A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the… |
| CVE-2025-9901 | Media (5.9) | 0.46% | — | 3 sept 2025 | A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached responses. This header ensures that responses vary appropriately based on request headers such as… |
| CVE-2025-4969 | Media (6.5) | 0.88% | — | 21 may 2025 | A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart… |
| CVE-2025-4945 | Baja (3.7) | 0.67% | — | 19 may 2025 | A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.