A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2 requests that cause authentication failures. This can lead to the application attempting to access memory that has already been freed, potentially causing application instability or crashes, resulting in a Denial of Service (DoS).
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade libsoup3-develUpgrade libsoup3-docUpgrade libsoup3 | May 13, 2026 | Mar 16, 2026 |
| Redhat_linux | — | Upgrade libsoup3-develUpgrade libsoup3Upgrade libsoup3-debugsourceUpgrade libsoup3-debuginfoUpgrade libsoup3-docNo solution exists | May 12, 2026 | Mar 16, 2026 |
| Rocky_linux | — | Upgrade libsoup3-debuginfoUpgrade libsoup3-develUpgrade libsoup3Upgrade libsoup3-debugsource | May 15, 2026 | May 13, 2026 |
| Suse | — | Upgrade libsoup-langUpgrade libsoup-3_0-0Upgrade typelib-1_0-Soup-3_0Upgrade libsoup-devel | Jun 1, 2026 | May 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub