A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 13, 2026 |
| Suse | — | Upgrade libsoup-langUpgrade typelib-1_0-Soup-2_4Upgrade typelib-1_0-Soup-3_0Upgrade libsoup-2_4-1-32bitUpgrade libsoup-devel-32bitUpgrade libsoup2-devel-32bitUpgrade libsoup-3_0-0Upgrade libsoup-develUpgrade libsoup2-develUpgrade libsoup-3_0-0-32bitUpgrade libsoup-2_4-1Upgrade libsoup2-lang | Feb 27, 2026 | Feb 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub