CVE-2026-2443
published 2026-02-13CVE-2026-2443: A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may…
PriorityP434medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.43%
34.9th percentile
A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsoup2.4 | < libsoup3 3.6.6-1 (forky) | libsoup3 3.6.6-1 (forky) |
| debian | libsoup3 | < libsoup3 3.6.6-1 (forky) | libsoup3 3.6.6-1 (forky) |
| debian | libsoup3 | — | — |
| gnome | libsoup | — | — |
| msrc | azl3_libsoup_3.4.4-11_on_azure_linux_3.0 | — | — |
| msrc | azl3_libsoup_3.4.4-12_on_azure_linux_3.0 | — | — |
| msrc | azl3_libsoup_3.4.4-14_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libsoup_3.0.4-10_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libsoup_3.0.4-12_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libsoup_3.0.4-13_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison.
ghsa_unreviewed·2026-06-22·CVSS 5.3
CVE-2026-12549 [MEDIUM] CWE-805 The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison.
The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.
GHSA
GHSA-hg24-p7xv-jhq8: A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems
ghsa_unreviewed·2026-02-13
CVE-2026-2443 [MEDIUM] CWE-125 GHSA-hg24-p7xv-jhq8: A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems
A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.
OSV
CVE-2026-2443: A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems
osv·2026-02-13·CVSS 5.3
CVE-2026-2443 [MEDIUM] CVE-2026-2443: A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems
A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.
Red Hat
libsoup: Out-of-Bounds Read in libsoup handle_partial_get() Leading to Heap Information Disclosure
vendor_redhat·2026-02-13·CVSS 5.3
CVE-2026-2443 [MEDIUM] CWE-125 libsoup: Out-of-Bounds Read in libsoup handle_partial_get() Leading to Heap Information Disclosure
libsoup: Out-of-Bounds Read in libsoup handle_partial_get() Leading to Heap Information Disclosure
A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.
A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remo
Microsoft
Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure
vendor_msrc·2026-02-10·CVSS 5.3
CVE-2026-2443 [MEDIUM] CWE-125 Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure
Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2026-2443: libsoup2.4 - A flaw was identified in libsoup, a widely used HTTP library in GNOME-based syst...
vendor_debian·2026·CVSS 5.3
CVE-2026-2443 [MEDIUM] CVE-2026-2443: libsoup2.4 - A flaw was identified in libsoup, a widely used HTTP library in GNOME-based syst...
A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.
Scope: local
bookworm: open
bullseye: open
trixie: open
Red Hat
libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer
vendor_redhat·2024-04-24·CVSS 4.8
CVE-2026-12549 [MEDIUM] CWE-805 libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer
libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer
The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.
The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.
Statement: This vu
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-12549 libsoup3: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
bugzilla·2026-06-18·CVSS 5.3
CVE-2026-12549 [MEDIUM] CVE-2026-12549 libsoup3: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
CVE-2026-12549 libsoup3: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-12549 mingw-libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
bugzilla·2026-06-18·CVSS 5.3
CVE-2026-12549 [MEDIUM] CVE-2026-12549 mingw-libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
CVE-2026-12549 mingw-libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-12549 libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
bugzilla·2026-06-18·CVSS 5.3
CVE-2026-12549 [MEDIUM] CVE-2026-12549 libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
CVE-2026-12549 libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-12549 libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer
bugzilla·2026-06-17·CVSS 4.8
CVE-2026-12549 [MEDIUM] CVE-2026-12549 libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer
CVE-2026-12549 libsoup: Incomplete fix for CVE-2026-2443: Range suffix overflow in libsoup SoupServer
https://gitlab.gnome.org/GNOME/libsoup/-/work_items/516
https://redhat.atlassian.net/browse/PSIRTSUPT-8846
Bugzilla
CVE-2026-2443 libsoup: Out-of-Bounds Read in libsoup handle_partial_get() Leading to Heap Information Disclosure
bugzilla·2026-02-13·CVSS 5.3
CVE-2026-2443 [MEDIUM] CVE-2026-2443 libsoup: Out-of-Bounds Read in libsoup handle_partial_get() Leading to Heap Information Disclosure
CVE-2026-2443 libsoup: Out-of-Bounds Read in libsoup handle_partial_get() Leading to Heap Information Disclosure
Out-of-bounds read vulnerability in the handle_partial_get() function of libsoup when processing HTTP Range headers. The issue occurs because the end value of the byte range is not properly validated against the total response size. If GLib is compiled with G_DISABLE_CHECKS, the call to g_bytes_new_from_bytes() may create a slice that exceeds the bounds of the original buffer. A specially crafted HTTP request with a large range value can cause heap memory beyond the intended response body to be returned to the attacker. This vulnerability can be triggered remotely without authentication or user interaction, potentially exposing portions of server heap memory.
Wiz
CVE-2026-2443 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-2443 [MEDIUM] CVE-2026-2443 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2443 :
Linux Debian vulnerability analysis and mitigation
A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.
Source : NVD
## 5.3
Score
Published February 13, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Linux Debian
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPS
2026-02-13
Published