Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2770▲ 14 respecto a la semana anterior
Críticas / altas1475▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.24% | — | LibsoupAI | 30/9/2026 | 30/9/2026 | A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither drains the declared body bytes nor closes the connection. On a keep-alive connection,… | |
| Pendiente de análisis | Alta (8.6) | 0.30% | — | LibsoupAI | 29/9/2026 | 29/9/2026 | A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could wrap, causing zlib to write past the allocated buffer and resulting in a heap buffer overflow. | |
| Pendiente de análisis | Alta (8.6) | 0.30% | — | LibsoupAI | 29/9/2026 | 30/9/2026 | A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full length, causing a heap buffer overflow. | |
| Pendiente de análisis | Alta (8.6) | 0.30% | — | LibsoupAI | 29/9/2026 | 30/9/2026 | A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer overflow while reading frame data. | |
| Pendiente de análisis | Alta (8.2) | 0.32% | — | LibsoupAI | 29/9/2026 | 29/9/2026 | A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the… | |
| Pendiente de análisis | Alta (8.6) | 0.22% | — | LibsoupAI | 29/9/2026 | 30/9/2026 | A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits of the underlying buffer type. A remote peer could send fragments that caused size truncation while the implementation still used the full length, leading… | |
| Pendiente de análisis | Alta (8.6) | 0.22% | — | LibsoupAI | 29/9/2026 | 29/9/2026 | A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash… | |
| Pendiente de análisis | Media (5.9) | 0.32% | — | Gnome LibsoupAI | 4/9/2026 | 8/9/2026 | A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then… | |
| Pendiente de análisis | Alta (7.6) | 0.27% | — | Gnome LibsoupAI | 4/9/2026 | 16/9/2026 | A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read… | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | Gnome LibsoupAI | 25/8/2026 | 28/8/2026 | An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed memory amplification when a client repeated the same range many times in a single Range header. Commit 9bb92f7a corrected merge correctness in… | |
| Pendiente de análisis | Media (5.3) | 0.23% | — | LibsoupAI | 20/8/2026 | 25/8/2026 | A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206… | |
| Analizada | Media (6.5) | 0.25% | — | Gnome LibsoupRedhat Enterprise Linux | 24/7/2026 | 24/8/2026 | A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information… | |
| Analizada | Alta (7.2) | 0.28% | — | Gnome LibsoupRedhat Enterprise Linux | 24/7/2026 | 24/8/2026 | A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing… | |
| Analizada | Media (6.5) | 0.38% | — | Gnome LibsoupRedhat Enterprise Linux | 24/7/2026 | 24/8/2026 | A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or… | |
| Analizada | Media (4.2) | 0.25% | — | Gnome LibsoupRedhat Enterprise Linux | 21/7/2026 | 24/8/2026 | A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated, leading to a heap buffer over-read. A remote attacker could use this flaw to crash an application… | |
| Aplazada | Media (6.5) | 0.39% | — | LibsoupAI | 14/7/2026 | 15/7/2026 | An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-multipart-input-stream.c, which does not adequately restrict or validate the size of incoming multipart boundary strings. When processing a… | |
| Aplazada | Media (5.9) | 0.35% | — | LibsoupAI | 14/7/2026 | 15/7/2026 | A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as when an HTTP/2 connection encounters window exhaustion or explicit stream resets. A remote, unauthenticated attacker acting as a… | |
| Aplazada | Media (5.9) | 0.50% | — | Gnome LibsoupAI | 14/7/2026 | 15/7/2026 | A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the library processes an HTTP/2 GOAWAY frame, it improperly handles the "Additional Debug Data" payload by assuming the data stream is a safely NUL-terminated C-string. Because… | |
| Aplazada | Alta (7.5) | 0.74% | — | LibsoupAI | 14/7/2026 | 24/9/2026 | A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this by… | |
| Aplazada | Alta (7.5) | 0.88% | — | LibsoupAI | 14/7/2026 | 24/9/2026 | A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via… | |
| Pendiente de análisis | Media (4.8) | 0.24% | — | Gnome LibsoupAI | 14/7/2026 | 16/9/2026 | The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked frame with a payload length near UINT64_MAX to trigger an OOB read in a libsoup-based… | |
| Analizada | Media (4.8) | 0.36% | — | Redhat Enterprise LinuxGnome Libsoup | 22/6/2026 | 8/7/2026 | The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206… | |
| Pendiente de análisis | Media (4.8) | 0.51% | — | Gnome LibsoupAI | 29/5/2026 | 21/7/2026 | A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` function by sending a malicious HTTP request. This vulnerability occurs when libsoup operates behind a non-libsoup proxy server or as a proxy in front of a non-libsoup… | |
| Analizada | Media (5.3) | 0.40% | — | Gnome LibsoupRedhat Enterprise Linux | 23/4/2026 | 17/6/2026 | A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP… | |
| Modificada | Alta (8.2) | 0.33% | — | Gnome LibsoupRedhat Enterprise Linux | 30/3/2026 | 17/6/2026 | A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential session hijacking or… |