A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding: chunked and Connection: keep-alive headers. A remote, unauthenticated client can exploit this by sending specially crafted requests, causing SoupServer to fail to close the connection as required by RFC 9112. This allows the attacker to smuggle additional requests over the persistent connection, leading to unintended request processing and potential denial-of-service (DoS) conditions.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade libsoup3-debugsourceUpgrade libsoup-develUpgrade libsoup3Upgrade libsoup-docUpgrade libsoup3-docUpgrade libsoupUpgrade libsoup3-develUpgrade libsoup-debugsourceUpgrade libsoup3-debuginfoUpgrade libsoup-debuginfo | May 28, 2026 | Feb 2, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 2, 2026 |
| Suse | — | Upgrade libsoup-2_4-1-32bitUpgrade libsoup2-develUpgrade typelib-1_0-Soup-2_4Upgrade libsoup2-langUpgrade typelib-1_0-Soup-3_0Upgrade libsoup-3_0-0-32bitUpgrade libsoup2-devel-32bitUpgrade libsoup-develUpgrade libsoup-devel-32bitUpgrade libsoup-3_0-0Upgrade libsoup-2_4-1Upgrade libsoup-lang | Mar 4, 2026 | Mar 3, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub