Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
432 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Gnome LibsoupRedhat Enterprise Linux | 17/3/2026 | 17/6/2026 | A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2 requests that cause authentication failures. This can lead to the application attempting… | |
| Analizada | Media (6.5) | 0.31% | — | Gnome LibsoupRedhat Enterprise Linux | 17/3/2026 | 17/6/2026 | A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for the injection of arbitrary header-value… | |
| Analizada | Media (6.5) | 0.37% | — | Gnome LibsoupRedhat Enterprise Linux | 17/3/2026 | 17/6/2026 | A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Carriage Return Line Feed) injection, occurs because the method value is not properly escaped during… | |
| Analizada | Media (5.5) | 0.35% | — | Gnome LibsoupRedhat Enterprise Linux | 17/3/2026 | 17/6/2026 | A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP headers. A remote attacker could exploit this to perform HTTP smuggling, where they can send hidden,… | |
| Analizada | Alta (7.3) | 0.48% | — | Gnome LibsoupRedhat Enterprise Linux | 12/3/2026 | 17/6/2026 | A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute. This vulnerability allows a remote attacker to capture a single valid authentication header and… | |
| Aplazada | Media (4.3) | 0.49% | — | Gnome GvfsAI | 26/2/2026 | 17/6/2026 | A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized sequences allow the attacker to terminate intended FTP commands and inject arbitrary FTP… | |
| Aplazada | Media (4.3) | 0.30% | — | Gnome GvfsAI | 26/2/2026 | 17/6/2026 | A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information and attempts to connect to the specified endpoint, allowing the malicious server to probe… | |
| Modificada | Media (5.3) | 0.46% | — | Gnome LibsoupRedhat Enterprise Linux | 13/2/2026 | 17/6/2026 | A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the… | |
| Analizada | Media (6.5) | 0.43% | 💥 PoC | Gnome LibsoupRedhat Enterprise Linux | 3/2/2026 | 17/6/2026 | A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk headers, such as lone line feed (LF) characters instead of the required carriage return… | |
| Aplazada | Alta (8.4) | 0.46% | — | Gnome Fonts ViewerAI | 29/1/2026 | 17/6/2026 | Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds write by crafting a malicious TTF font file. Attackers can generate a specially crafted TTF file with an oversized pattern to exhaust memory through repeated malloc() calls and potentially crash the… | |
| Analizada | Media (5.8) | 0.28% | — | Gnome LibsoupRedhat Enterprise Linux | 28/1/2026 | 17/6/2026 | A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result,… | |
| Analizada | Media (5.3) | 0.35% | — | Gnome LibsoupRedhat Enterprise Linux | 28/1/2026 | 17/6/2026 | A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be… | |
| Aplazada | Media (5.4) | 0.37% | — | Gnome GlibAI | 27/1/2026 | 17/6/2026 | A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause… | |
| Aplazada | Baja (2.8) | 0.16% | — | Gnome GlibAI | 27/1/2026 | 17/6/2026 | A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a… | |
| Aplazada | Media (4.2) | 0.35% | — | Gnome GlibAI | 27/1/2026 | 17/6/2026 | A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large… | |
| Analizada | Media (5.3) | 0.37% | — | Gnome LibsoupRedhat Enterprise Linux | 27/1/2026 | 17/6/2026 | A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted… | |
| Aplazada | Alta (8) | 0.40% | — | Gnome EpiphanyAI | 23/1/2026 | 17/6/2026 | A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user interaction. This design can be misused to exploit vulnerabilities within those handlers, making them appear remotely exploitable. The browser fails to properly warn or gate this action, resulting in… | |
| Aplazada | Baja (3.7) | 0.44% | — | Gnome GlibAI | 21/1/2026 | 17/6/2026 | A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer… | |
| Aplazada | Alta (8.6) | 0.61% | — | Gnome LibsoupAI | 8/1/2026 | 15/7/2026 | A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can overflow due to improper use of signed integers. This results in incorrect memory allocation… | |
| Modificada | Media (6.5) | 0.58% | — | Gnome GlibRedhat OpenshiftRedhat Enterprise Linux | 11/12/2025 | 7/10/2026 | A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values. | |
| Modificada | Crítica (9.8) | 0.83% | — | Gnome GlibRedhat Enterprise Linux | 10/12/2025 | 2/10/2026 | A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings. | |
| Aplazada | Media (4.7) | 0.20% | — | KDE ConnectAIKDE Connect IOSAIKDE Connect AndroidAIGnome GsconnectAI+1 | 5/12/2025 | 17/6/2026 | The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49. | |
| Aplazada | Media (4.3) | 0.12% | — | KDE ConnectAIKDE Connect AndroidAIKDE Connect IOSAIGnome GsconnectAI+1 | 5/12/2025 | 17/6/2026 | In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before… | |
| Modificada | Alta (7.7) | 0.32% | — | Redhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little EndianRedhat Codeready Linux Builder FOR X86 64+25 | 26/11/2025 | 31/8/2026 | A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow,… | |
| Rechazada | Sin puntuar | — | — | Gnome Libxml2AI | 7/11/2025 | 20/11/2025 | Rejected reason: This CVE was assigned for a libxml2 issue#1012 but later deemed not valid. Ref.: https://gitlab.gnome.org/GNOME/libxml2/-/issues/1012#note_2608283 |