CVE-2026-1467
published 2026-01-27CVE-2026-1467: A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is…
PriorityP433medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.31%
23.3th percentile
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allowing them to inject additional HTTP headers or complete HTTP request bodies. This can lead to unintended or unauthorized HTTP requests being forwarded by the proxy, potentially impacting downstream services.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsoup2.4 | < libsoup3 3.6.5-8 (forky) | libsoup3 3.6.5-8 (forky) |
| debian | libsoup3 | < libsoup3 3.6.5-8 (forky) | libsoup3 3.6.5-8 (forky) |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libsoup vulnerabilities
vendor_ubuntu·2026-02-08·CVSS 5.8
CVE-2026-1539 [MEDIUM] libsoup vulnerabilities
Title: libsoup vulnerabilities
Summary: Several security issues were fixed in libsoup.
It was discovered that libsoup did not correctly handle certain
URL-decoded input, which could allow for HTTP header injection. A remote
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-1467, CVE-2026-1536)
It was discovered that libsoup did not correctly handle removal of the
Proxy-Authorization header. A remote attacker could possibly use this
issue to leak sensitive information. (CVE-2026-1539)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libsoup: libsoup: HTTP header injection via specially crafted URLs when an HTTP proxy is configured
vendor_redhat·2026-01-27·CVSS 5.8
CVE-2026-1467 [MEDIUM] CWE-93 libsoup: libsoup: HTTP header injection via specially crafted URLs when an HTTP proxy is configured
libsoup: libsoup: HTTP header injection via specially crafted URLs when an HTTP proxy is configured
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allowing them to inject additional HTTP headers or complete HTTP request bodies. This can lead to unintended or unauthorized HTTP requests being forwarded by the proxy, potentially impacting downstream services.
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs whe
Debian
CVE-2026-1467: libsoup2.4 - A flaw was found in libsoup, an HTTP client library. This vulnerability, known a...
vendor_debian·2026·CVSS 5.8
CVE-2026-1467 [MEDIUM] CVE-2026-1467: libsoup2.4 - A flaw was found in libsoup, an HTTP client library. This vulnerability, known a...
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allowing them to inject additional HTTP headers or complete HTTP request bodies. This can lead to unintended or unauthorized HTTP requests being forwarded by the proxy, potentially impacting downstream services.
Scope: local
bookworm: open
bullseye: open
trixie: open
OSV
libsoup3 vulnerabilities
osv·2026-02-08·CVSS 5.3
CVE-2026-1467 [MEDIUM] libsoup3 vulnerabilities
libsoup3 vulnerabilities
It was discovered that libsoup did not correctly handle certain
URL-decoded input, which could allow for HTTP header injection. A remote
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-1467, CVE-2026-1536)
It was discovered that libsoup did not correctly handle removal of the
Proxy-Authorization header. A remote attacker could possibly use this
issue to leak sensitive information. (CVE-2026-1539)
GHSA
GHSA-8pm5-xr39-vfv3: A flaw was found in libsoup, an HTTP client library
ghsa_unreviewed·2026-01-27
CVE-2026-1467 [MEDIUM] CWE-93 GHSA-8pm5-xr39-vfv3: A flaw was found in libsoup, an HTTP client library
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allowing them to inject additional HTTP headers or complete HTTP request bodies. This can lead to unintended or unauthorized HTTP requests being forwarded by the proxy, potentially impacting downstream services.
OSV
CVE-2026-1467: A flaw was found in libsoup, an HTTP client library
osv·2026-01-27·CVSS 5.3
CVE-2026-1467 [MEDIUM] CVE-2026-1467: A flaw was found in libsoup, an HTTP client library
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allowing them to inject additional HTTP headers or complete HTTP request bodies. This can lead to unintended or unauthorized HTTP requests being forwarded by the proxy, potentially impacting downstream services.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-1467 libsoup: libsoup: HTTP header injection via specially crafted URLs when an HTTP proxy is configured [fedora-42]
bugzilla·2026-01-27·CVSS 5.3
CVE-2026-1467 [MEDIUM] CVE-2026-1467 libsoup: libsoup: HTTP header injection via specially crafted URLs when an HTTP proxy is configured [fedora-42]
CVE-2026-1467 libsoup: libsoup: HTTP header injection via specially crafted URLs when an HTTP proxy is configured [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a c
Bugzilla
CVE-2026-1467 libsoup: libsoup: HTTP header injection via specially crafted URLs when an HTTP proxy is configured
bugzilla·2026-01-27·CVSS 5.3
CVE-2026-1467 [MEDIUM] CVE-2026-1467 libsoup: libsoup: HTTP header injection via specially crafted URLs when an HTTP proxy is configured
CVE-2026-1467 libsoup: libsoup: HTTP header injection via specially crafted URLs when an HTTP proxy is configured
CRLF Injection vulnerability in the libsoup HTTP client library when an HTTP proxy is configured. The issue is caused by improper sanitization of URL-decoded input used to populate the Host header during request creation in the SoupSession workflow. By supplying a specially crafted URL containing CRLF sequences, an attacker can inject additional HTTP headers or complete HTTP request bodies. Exploitation requires a victim application to process an attacker-controlled URL while using an HTTP proxy. Successful exploitation may allow unintended or unauthorized HTTP requests to be forwarded by the proxy, potentially impacting downstream services, but does not directly compromise th
Bugzilla
CVE-2026-1467 mingw-libsoup: libsoup: HTTP header injection via specially crafted URLs when an HTTP proxy is configured [fedora-42]
bugzilla·2026-01-27·CVSS 5.3
CVE-2026-1467 [MEDIUM] CVE-2026-1467 mingw-libsoup: libsoup: HTTP header injection via specially crafted URLs when an HTTP proxy is configured [fedora-42]
CVE-2026-1467 mingw-libsoup: libsoup: HTTP header injection via specially crafted URLs when an HTTP proxy is configured [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it
Wiz
CVE-2026-1467 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.8
CVE-2026-1467 [MEDIUM] CVE-2026-1467 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1467 :
CBL Mariner vulnerability analysis and mitigation
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allowing them to inject additional HTTP headers or complete HTTP request bodies. This can lead to unintended or unauthorized HTTP requests being forwarded by the proxy, potentially impacting downstream services.
Source : NVD
## 5.3
Score
Published January 27, 2026
Severity MEDIUM
CNA Score 5.8
Affected Technologies
CBL Mariner
Linux Debian
Has Public Exploit Yes
H
2026-01-27
Published