CVE-2026-1760
published 2026-02-02CVE-2026-1760: A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding…
PriorityP433medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.42%
34.7th percentile
A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding: chunked and Connection: keep-alive headers. A remote, unauthenticated client can exploit this by sending specially crafted requests, causing SoupServer to fail to close the connection as required by RFC 9112. This allows the attacker to smuggle additional requests over the persistent connection, leading to unintended request processing and potential denial-of-service (DoS) conditions.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsoup2.4 | < libsoup3 3.6.5-8 (forky) | libsoup3 3.6.5-8 (forky) |
| debian | libsoup3 | < libsoup3 3.6.5-8 (forky) | libsoup3 3.6.5-8 (forky) |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libsoup: SoupServer: Denial of Service via HTTP request smuggling
vendor_redhat·2026-02-02·CVSS 5.3
CVE-2026-1760 [MEDIUM] CWE-444 libsoup: SoupServer: Denial of Service via HTTP request smuggling
libsoup: SoupServer: Denial of Service via HTTP request smuggling
A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding: chunked and Connection: keep-alive headers. A remote, unauthenticated client can exploit this by sending specially crafted requests, causing SoupServer to fail to close the connection as required by RFC 9112. This allows the attacker to smuggle additional requests over the persistent connection, leading to unintended request processing and potential denial-of-service (DoS) conditions.
A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding: chunked and Connection:
Debian
CVE-2026-1760: libsoup2.4 - A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs...
vendor_debian·2026·CVSS 5.3
CVE-2026-1760 [MEDIUM] CVE-2026-1760: libsoup2.4 - A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs...
A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding: chunked and Connection: keep-alive headers. A remote, unauthenticated client can exploit this by sending specially crafted requests, causing SoupServer to fail to close the connection as required by RFC 9112. This allows the attacker to smuggle additional requests over the persistent connection, leading to unintended request processing and potential denial-of-service (DoS) conditions.
Scope: local
bookworm: open
bullseye: open
trixie: open
GHSA
GHSA-58g3-53qw-g6m8: A flaw was found in SoupServer
ghsa_unreviewed·2026-02-02
CVE-2026-1760 [MEDIUM] CWE-444 GHSA-58g3-53qw-g6m8: A flaw was found in SoupServer
A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding: chunked and Connection: keep-alive headers. A remote, unauthenticated client can exploit this by sending specially crafted requests, causing SoupServer to fail to close the connection as required by RFC 9112. This allows the attacker to smuggle additional requests over the persistent connection, leading to unintended request processing and potential denial-of-service (DoS) conditions.
OSV
CVE-2026-1760: A flaw was found in SoupServer
osv·2026-02-02·CVSS 5.3
CVE-2026-1760 [MEDIUM] CVE-2026-1760: A flaw was found in SoupServer
A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding: chunked and Connection: keep-alive headers. A remote, unauthenticated client can exploit this by sending specially crafted requests, causing SoupServer to fail to close the connection as required by RFC 9112. This allows the attacker to smuggle additional requests over the persistent connection, leading to unintended request processing and potential denial-of-service (DoS) conditions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-1760 libsoup: SoupServer: Denial of Service via HTTP request smuggling
bugzilla·2026-02-02·CVSS 5.3
CVE-2026-1760 [MEDIUM] CVE-2026-1760 libsoup: SoupServer: Denial of Service via HTTP request smuggling
CVE-2026-1760 libsoup: SoupServer: Denial of Service via HTTP request smuggling
HTTP request smuggling vulnerability in SoupServer due to improper handling of requests containing Transfer-Encoding: chunked combined with Connection: keep-alive. Although SoupServer correctly ignores the Content-Length header, it fails to close the connection after responding, in violation of RFC 9112. This allows remaining chunked data to be processed as a subsequent HTTP request. A remote, unauthenticated client can exploit this behavior to smuggle additional requests over a persistent connection, leading to unintended request processing and potential denial-of-service conditions.
Wiz
CVE-2026-1760 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-1760 [MEDIUM] CVE-2026-1760 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1760 :
CBL Mariner vulnerability analysis and mitigation
A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding: chunked and Connection: keep-alive headers. A remote, unauthenticated client can exploit this by sending specially crafted requests, causing SoupServer to fail to close the connection as required by RFC 9112. This allows the attacker to smuggle additional requests over the persistent connection, leading to unintended request processing and potential denial-of-service (DoS) conditions.
Source : NVD
## 5.3
Score
Published February 2, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
CBL Mariner
Linux Debian
Has Public Exploit No
Has CISA KEV Exp
2026-02-02
Published