CVE-2026-2369
published 2026-03-19CVE-2026-2369: A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This…
PriorityP348critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.42%
34.0th percentile
A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially access sensitive information or cause an application level denial of service.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsoup2.4 | < libsoup3 3.6.6-1 (forky) | libsoup3 3.6.6-1 (forky) |
| debian | libsoup3 | < libsoup3 3.6.6-1 (forky) | libsoup3 3.6.6-1 (forky) |
| msrc | azl3_libsoup_3.4.4-12_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libsoup_3.0.4-12_on_cbl_mariner_2.0 | — | — |
| ubuntu | libsoup2.4 | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu9.1CRITICAL
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libsoup vulnerabilities
vendor_ubuntu·2026-07-09·CVSS 9.1
CVE-2026-2369 [CRITICAL] libsoup vulnerabilities
Title: libsoup vulnerabilities
Summary: Several security issues were fixed in libsoup.
Eric Su and Samuel Dainard discovered that libsoup incorrectly handled
content with zero-length resources. An attacker could possibly use this
issue to trigger a buffer over-read, resulting in information disclosure
or a denial of service. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and
Ubuntu 26.04 LTS. (CVE-2026-2369)
Kona Arctic discovered that libsoup did not properly protect sensitive
cookies when establishing HTTPS tunnels through an HTTP proxy. An
attacker could possibly use this issue to intercept session cookies,
resulting in session hijacking or user impersonation. (CVE-2026-5119)
Instructions: In general, a standard system
Microsoft
Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources
vendor_msrc·2026-03-10·CVSS 6.5
CVE-2026-2369 [MEDIUM] CWE-191 Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources
Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Red Hat
libsoup: libsoup: Buffer overread due to integer underflow when handling zero-length resources
vendor_redhat·2026-02-11·CVSS 6.5
CVE-2026-2369 [MEDIUM] CWE-191 libsoup: libsoup: Buffer overread due to integer underflow when handling zero-length resources
libsoup: libsoup: Buffer overread due to integer underflow when handling zero-length resources
A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially access sensitive information or cause an application level denial of service.
A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially access sensitive information or cause an application level denial of service.
Statement: This MODERATE impact flaw in libsoup arises from an integer underflow when processing content with zero-length resources, leading to a buffer o
Debian
CVE-2026-2369: libsoup2.4 - A flaw was found in libsoup. An integer underflow vulnerability occurs when proc...
vendor_debian·2026·CVSS 6.5
CVE-2026-2369 [MEDIUM] CVE-2026-2369: libsoup2.4 - A flaw was found in libsoup. An integer underflow vulnerability occurs when proc...
A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially access sensitive information or cause an application level denial of service.
Scope: local
bookworm: open
bullseye: open
trixie: open
OSV
CVE-2026-2369: A flaw was found in libsoup
osv·2026-03-19·CVSS 6.5
CVE-2026-2369 [MEDIUM] CVE-2026-2369: A flaw was found in libsoup
A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially access sensitive information or cause an application level denial of service.
GHSA
GHSA-rm63-3cv3-qm5w: A flaw was found in libsoup
ghsa_unreviewed·2026-03-19
CVE-2026-2369 [MEDIUM] CWE-191 GHSA-rm63-3cv3-qm5w: A flaw was found in libsoup
A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially access sensitive information or cause an application level denial of service.
No detection rules found.
No public exploits indexed.
2026-03-19
Published