cbcvebase.
CVE-2026-1761
published 2026-02-02

CVE-2026-1761: A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length…

PriorityP263high8.6CVSS 3.1
AVNACLPRNUINSUCLIHAL
EPSS
0.95%
57.2th percentile
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to memory corruption. This issue may result in application crashes or arbitrary code execution in applications that process untrusted server responses, and it does not require authentication or user interaction.

Affected

2 ranges
VendorProductVersion rangeFixed in
debianlibsoup2.4< libsoup3 3.6.5-8 (forky)libsoup3 3.6.5-8 (forky)
debianlibsoup3< libsoup3 3.6.5-8 (forky)libsoup3 3.6.5-8 (forky)

Detection & IOCsextracted from sources · hover to see the quote

  • Focus detection on the specific function soup_filter_input_stream_read_until() as the vulnerable code path; crash telemetry or stack canary violations in this function are indicative of exploitation attempts.
  • Exploitation does not require authentication or user interaction; any application using libsoup to process HTTP responses from untrusted servers is at risk. Network-level detection should look for anomalously large or malformed multipart/form-data HTTP responses.
  • ·Red Hat recommends restricting vulnerable libsoup-based applications to only communicate with trusted endpoints as a mitigation; network egress filtering should be applied to reduce exposure.
  • ·libsoup on Red Hat Enterprise Linux 6 is out of support scope and will not receive a patch; systems running RHEL 6 with libsoup remain permanently exposed.
  • ·Debian bookworm, bullseye, and trixie all have open (unpatched) status for this CVE at time of source capture.

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.