CVE-2026-1761
published 2026-02-02CVE-2026-1761: A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length…
PriorityP263high8.6CVSS 3.1
AVNACLPRNUINSUCLIHAL
EPSS
0.95%
57.2th percentile
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to memory corruption. This issue may result in application crashes or arbitrary code execution in applications that process untrusted server responses, and it does not require authentication or user interaction.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsoup2.4 | < libsoup3 3.6.5-8 (forky) | libsoup3 3.6.5-8 (forky) |
| debian | libsoup3 | < libsoup3 3.6.5-8 (forky) | libsoup3 3.6.5-8 (forky) |
Detection & IOCsextracted from sources · hover to see the quote
- →Focus detection on the specific function soup_filter_input_stream_read_until() as the vulnerable code path; crash telemetry or stack canary violations in this function are indicative of exploitation attempts. ↗
- →Exploitation does not require authentication or user interaction; any application using libsoup to process HTTP responses from untrusted servers is at risk. Network-level detection should look for anomalously large or malformed multipart/form-data HTTP responses. ↗
- ·Red Hat recommends restricting vulnerable libsoup-based applications to only communicate with trusted endpoints as a mitigation; network egress filtering should be applied to reduce exposure. ↗
- ·libsoup on Red Hat Enterprise Linux 6 is out of support scope and will not receive a patch; systems running RHEL 6 with libsoup remain permanently exposed. ↗
- ·Debian bookworm, bullseye, and trixie all have open (unpatched) status for this CVE at time of source capture. ↗
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libsoup: Stack-Based Buffer Overflow in libsoup Multipart Response Parsingmultipart HTTP response
vendor_redhat·2026-02-02·CVSS 8.6
CVE-2026-1761 [HIGH] CWE-121 libsoup: Stack-Based Buffer Overflow in libsoup Multipart Response Parsingmultipart HTTP response
libsoup: Stack-Based Buffer Overflow in libsoup Multipart Response Parsingmultipart HTTP response
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to memory corruption. This issue may result in application crashes or arbitrary code execution in applications that process untrusted server responses, and it does not require authentication or user interaction.
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by send
Debian
CVE-2026-1761: libsoup2.4 - A flaw was found in libsoup. This stack-based buffer overflow vulnerability occu...
vendor_debian·2026·CVSS 8.6
CVE-2026-1761 [HIGH] CVE-2026-1761: libsoup2.4 - A flaw was found in libsoup. This stack-based buffer overflow vulnerability occu...
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to memory corruption. This issue may result in application crashes or arbitrary code execution in applications that process untrusted server responses, and it does not require authentication or user interaction.
Scope: local
bookworm: open
bullseye: open
trixie: open
GHSA
GHSA-6j8r-j98h-9g9f: A flaw was found in libsoup
ghsa_unreviewed·2026-02-02
CVE-2026-1761 [HIGH] CWE-121 GHSA-6j8r-j98h-9g9f: A flaw was found in libsoup
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to memory corruption. This issue may result in application crashes or arbitrary code execution in applications that process untrusted server responses, and it does not require authentication or user interaction.
OSV
CVE-2026-1761: A flaw was found in libsoup
osv·2026-02-02·CVSS 8.6
CVE-2026-1761 [HIGH] CVE-2026-1761: A flaw was found in libsoup
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to memory corruption. This issue may result in application crashes or arbitrary code execution in applications that process untrusted server responses, and it does not require authentication or user interaction.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-1761 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-1761 [HIGH] CVE-2026-1761 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1761 :
Rocky Linux vulnerability analysis and mitigation
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to memory corruption. This issue may result in application crashes or arbitrary code execution in applications that process untrusted server responses, and it does not require authentication or user interaction.
Source : NVD
## 8.6
Score
Published February 2, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Explo
Bugzilla
CVE-2026-1761 libsoup: Stack-Based Buffer Overflow in libsoup Multipart Response Parsingmultipart HTTP response
bugzilla·2026-02-02·CVSS 8.6
CVE-2026-1761 [HIGH] CVE-2026-1761 libsoup: Stack-Based Buffer Overflow in libsoup Multipart Response Parsingmultipart HTTP response
CVE-2026-1761 libsoup: Stack-Based Buffer Overflow in libsoup Multipart Response Parsingmultipart HTTP response
Stack-based buffer overflow vulnerability in libsoup’s multipart/form-data response parsing logic. The flaw exists in the soup_filter_input_stream_read_until() function, where an incorrect length calculation may cause more data to be copied than the size of the caller-provided buffer. When a specially crafted multipart HTTP response is processed, libsoup can write past the end of a stack buffer, resulting in memory corruption. This issue can be triggered remotely without authentication or user interaction, potentially leading to application crashes or arbitrary code execution in applications that parse untrusted server responses.
Discussion:
This issue has been addressed in th
https://access.redhat.com/errata/RHSA-2026:1948https://access.redhat.com/errata/RHSA-2026:2005https://access.redhat.com/errata/RHSA-2026:2006https://access.redhat.com/errata/RHSA-2026:2007https://access.redhat.com/errata/RHSA-2026:2008https://access.redhat.com/errata/RHSA-2026:2049https://access.redhat.com/errata/RHSA-2026:2182https://access.redhat.com/errata/RHSA-2026:2214https://access.redhat.com/errata/RHSA-2026:2215https://access.redhat.com/errata/RHSA-2026:2216https://access.redhat.com/errata/RHSA-2026:2396https://access.redhat.com/errata/RHSA-2026:2402https://access.redhat.com/errata/RHSA-2026:2410https://access.redhat.com/errata/RHSA-2026:2512https://access.redhat.com/errata/RHSA-2026:2513https://access.redhat.com/errata/RHSA-2026:2514https://access.redhat.com/errata/RHSA-2026:2528https://access.redhat.com/errata/RHSA-2026:2529https://access.redhat.com/errata/RHSA-2026:2628https://access.redhat.com/errata/RHSA-2026:2844https://access.redhat.com/security/cve/CVE-2026-1761https://bugzilla.redhat.com/show_bug.cgi?id=2435961https://gitlab.gnome.org/GNOME/libsoup/-/issues/493https://access.redhat.com/errata/RHSA-2026:1948https://access.redhat.com/errata/RHSA-2026:2005https://access.redhat.com/errata/RHSA-2026:2006https://access.redhat.com/errata/RHSA-2026:2007https://access.redhat.com/errata/RHSA-2026:2008https://access.redhat.com/errata/RHSA-2026:2049https://access.redhat.com/errata/RHSA-2026:2182https://access.redhat.com/errata/RHSA-2026:2214https://access.redhat.com/errata/RHSA-2026:2215https://access.redhat.com/errata/RHSA-2026:2216https://access.redhat.com/errata/RHSA-2026:2396https://access.redhat.com/errata/RHSA-2026:2402https://access.redhat.com/errata/RHSA-2026:2410https://access.redhat.com/errata/RHSA-2026:2512https://access.redhat.com/errata/RHSA-2026:2513https://access.redhat.com/errata/RHSA-2026:2514https://access.redhat.com/errata/RHSA-2026:2528https://access.redhat.com/errata/RHSA-2026:2529https://access.redhat.com/errata/RHSA-2026:2628https://access.redhat.com/errata/RHSA-2026:2844https://access.redhat.com/security/cve/CVE-2026-1761https://bugzilla.redhat.com/show_bug.cgi?id=2435961https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1761.json
2026-02-02
Published