CVE-2026-1536
published 2026-01-28CVE-2026-1536: A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences…
PriorityP433medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.30%
21.7th percentile
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to HTTP header injection or HTTP response splitting without requiring authentication or user interaction.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsoup2.4 | < libsoup3 3.6.5-8 (forky) | libsoup3 3.6.5-8 (forky) |
| debian | libsoup3 | < libsoup3 3.6.5-8 (forky) | libsoup3 3.6.5-8 (forky) |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libsoup3 vulnerabilities
osv·2026-02-08·CVSS 5.3
CVE-2026-1467 [MEDIUM] libsoup3 vulnerabilities
libsoup3 vulnerabilities
It was discovered that libsoup did not correctly handle certain
URL-decoded input, which could allow for HTTP header injection. A remote
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-1467, CVE-2026-1536)
It was discovered that libsoup did not correctly handle removal of the
Proxy-Authorization header. A remote attacker could possibly use this
issue to leak sensitive information. (CVE-2026-1539)
GHSA
GHSA-x4cc-vgcc-h5h4: A flaw was found in libsoup
ghsa_unreviewed·2026-01-28
CVE-2026-1536 [MEDIUM] CWE-93 GHSA-x4cc-vgcc-h5h4: A flaw was found in libsoup
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to HTTP header injection or HTTP response splitting without requiring authentication or user interaction.
OSV
CVE-2026-1536: A flaw was found in libsoup
osv·2026-01-28·CVSS 5.3
CVE-2026-1536 [MEDIUM] CVE-2026-1536: A flaw was found in libsoup
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to HTTP header injection or HTTP response splitting without requiring authentication or user interaction.
Ubuntu
libsoup vulnerabilities
vendor_ubuntu·2026-02-08·CVSS 5.8
CVE-2026-1539 [MEDIUM] libsoup vulnerabilities
Title: libsoup vulnerabilities
Summary: Several security issues were fixed in libsoup.
It was discovered that libsoup did not correctly handle certain
URL-decoded input, which could allow for HTTP header injection. A remote
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-1467, CVE-2026-1536)
It was discovered that libsoup did not correctly handle removal of the
Proxy-Authorization header. A remote attacker could possibly use this
issue to leak sensitive information. (CVE-2026-1539)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libsoup: libsoup: HTTP header injection or response splitting via CRLF injection in Content-Disposition header
vendor_redhat·2026-01-28·CVSS 5.8
CVE-2026-1536 [MEDIUM] CWE-93 libsoup: libsoup: HTTP header injection or response splitting via CRLF injection in Content-Disposition header
libsoup: libsoup: HTTP header injection or response splitting via CRLF injection in Content-Disposition header
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to HTTP header injection or HTTP response splitting without requiring authentication or user interaction.
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when
Debian
CVE-2026-1536: libsoup2.4 - A flaw was found in libsoup. An attacker who can control the input for the Conte...
vendor_debian·2026·CVSS 5.8
CVE-2026-1536 [MEDIUM] CVE-2026-1536: libsoup2.4 - A flaw was found in libsoup. An attacker who can control the input for the Conte...
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to HTTP header injection or HTTP response splitting without requiring authentication or user interaction.
Scope: local
bookworm: open
bullseye: open
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-1536 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.8
CVE-2026-1536 [MEDIUM] CVE-2026-1536 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1536 :
CBL Mariner vulnerability analysis and mitigation
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to HTTP header injection or HTTP response splitting without requiring authentication or user interaction.
Source : NVD
## 5.3
Score
Published January 28, 2026
Severity MEDIUM
CNA Score 5.8
Affected Technologies
CBL Mariner
Linux Debian
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percen
Bugzilla
CVE-2026-53143 kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
bugzilla·2026-06-25
CVE-2026-53143 [HIGH] CVE-2026-53143 kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
CVE-2026-53143 kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
The v11 MQD manager incorrectly assigned the CP-compute variants of
checkpoint_mqd/restore_mqd for KFD_MQD_TYPE_SDMA queues. These functions
use sizeof(struct v11_compute_mqd) (2048 bytes) instead of sizeof(struct
v11_sdma_mqd) (512 bytes), causing a 1536-byte overflow.
During CRIU checkpoint of an SDMA queue on Navi3x:
- checkpoint_mqd() reads 2048 bytes from a 512-byte SDMA MQD buffer,
leaking 1536 bytes of adjacent GTT memory to userspace
During CRIU restore:
- restore_mqd() writes 2048 bytes into a 512-byte SDMA MQD buffer,
corrupting 1536 bytes
Bugzilla
CVE-2026-1536 libsoup: libsoup: HTTP header injection or response splitting via CRLF injection in Content-Disposition header
bugzilla·2026-01-28·CVSS 5.3
CVE-2026-1536 [MEDIUM] CVE-2026-1536 libsoup: libsoup: HTTP header injection or response splitting via CRLF injection in Content-Disposition header
CVE-2026-1536 libsoup: libsoup: HTTP header injection or response splitting via CRLF injection in Content-Disposition header
CRLF injection vulnerability in the soup_message_headers_set_content_disposition() function of the libsoup HTTP library. The issue occurs because this function internally uses soup_message_headers_append_common(), which does not enforce character restrictions on header values. As a result, an attacker who can control the input used for the Content-Disposition header can inject CRLF sequences into the header value. When the HTTP request or response is later constructed, these sequences are interpreted verbatim, allowing arbitrary HTTP headers to be injected. This can lead to header injection or HTTP response splitting without authentication or user interaction.
2026-01-28
Published