CVE-2026-12549
published 2026-06-22CVE-2026-12549: The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client…
PriorityP425medium4.8CVSS 3.1
AVNACHPRNUINSUCLINAL
EPSS
0.33%
24.4th percentile
The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsoup3 | — | — |
| gnome | libsoup | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison.
ghsa_unreviewed·2026-06-22·CVSS 5.3
CVE-2026-12549 [MEDIUM] CWE-805 The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison.
The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.
VulDB
Red Hat Enterprise Linux up to 10 buffer access with incorrect length value (Nessus ID 321970)
vuldb·2026-06-22·CVSS 4.8
CVE-2026-12549 [MEDIUM] Red Hat Enterprise Linux up to 10 buffer access with incorrect length value (Nessus ID 321970)
A vulnerability labeled as problematic has been found in Red Hat Enterprise Linux 6/7/8/9/10. This affects an unknown part. Such manipulation leads to buffer access with incorrect length value.
This vulnerability is traded as CVE-2026-12549. The attack may be launched remotely. There is no exploit available.
Applying a patch is advised to resolve this issue.
Red Hat
libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer
vendor_redhat·2024-04-24·CVSS 4.8
CVE-2026-12549 [MEDIUM] CWE-805 libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer
libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer
The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.
The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.
Statement: This vu
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-12549 libsoup3: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
bugzilla·2026-06-18·CVSS 5.3
CVE-2026-12549 [MEDIUM] CVE-2026-12549 libsoup3: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
CVE-2026-12549 libsoup3: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-12549 mingw-libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
bugzilla·2026-06-18·CVSS 5.3
CVE-2026-12549 [MEDIUM] CVE-2026-12549 mingw-libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
CVE-2026-12549 mingw-libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-12549 libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
bugzilla·2026-06-18·CVSS 5.3
CVE-2026-12549 [MEDIUM] CVE-2026-12549 libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
CVE-2026-12549 libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-12549 libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer
bugzilla·2026-06-17·CVSS 4.8
CVE-2026-12549 [MEDIUM] CVE-2026-12549 libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer
CVE-2026-12549 libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer
https://gitlab.gnome.org/GNOME/libsoup/-/work_items/516
https://redhat.atlassian.net/browse/PSIRTSUPT-8846
Wiz
CVE-2025-12549 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2025-12549 [CRITICAL] CVE-2025-12549 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-12549 :
WordPress vulnerability analysis and mitigation
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech Rozy - Flower Shop rozy allows PHP Local File Inclusion.This issue affects Rozy - Flower Shop: from n/a through <= 1.2.25.
Source : NVD
## 9.8
Score
Published January 8, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
WordPress
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 18.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
rozy
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploita
2026-06-22
Published