CVE-2026-3632
published 2026-03-17CVE-2026-3632: A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate…
PriorityP434medium5.5CVSS 3.1
AVNACLPRLUIRSUCLILAL
EPSS
0.21%
11.0th percentile
A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP headers. A remote attacker could exploit this to perform HTTP smuggling, where they can send hidden, malicious requests alongside legitimate ones. In certain situations, this could lead to Server-Side Request Forgery (SSRF), enabling an attacker to force the server to make unauthorized requests to other internal or external systems. The impact is low, as SoupServer is not actually used in internet infrastructure.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsoup2.4 | — | — |
| debian | libsoup3 | — | — |
| msrc | azl3_libsoup_3.4.4-12_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libsoup_3.0.4-12_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
osv5.5MEDIUM
vendor_debian3.9LOW
vendor_msrc3.9LOW
vendor_redhat3.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v5mp-vx4p-jwp6: A flaw was found in libsoup, a library used by applications to send network requests
ghsa_unreviewed·2026-03-17
CVE-2026-3632 [LOW] CWE-1286 GHSA-v5mp-vx4p-jwp6: A flaw was found in libsoup, a library used by applications to send network requests
A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP headers. A remote attacker could exploit this to perform HTTP smuggling, where they can send hidden, malicious requests alongside legitimate ones. In certain situations, this could lead to Server-Side Request Forgery (SSRF), enabling an attacker to force the server to make unauthorized requests to other internal or external systems. The impact is low, as SoupServer is not actually used in internet infrastructure.
OSV
CVE-2026-3632: A flaw was found in libsoup, a library used by applications to send network requests
osv·2026-03-17·CVSS 5.5
CVE-2026-3632 [MEDIUM] CVE-2026-3632: A flaw was found in libsoup, a library used by applications to send network requests
A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP headers. A remote attacker could exploit this to perform HTTP smuggling, where they can send hidden, malicious requests alongside legitimate ones. In certain situations, this could lead to Server-Side Request Forgery (SSRF), enabling an attacker to force the server to make unauthorized requests to other internal or external systems. The impact is low, as SoupServer is not actually used in internet infrastructure.
Microsoft
Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
vendor_msrc·2026-03-10·CVSS 3.9
CVE-2026-3632 [LOW] CWE-1286 Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Red Hat
libsoup: libsoup: HTTP Smuggling and Server-Side Request Forgery via Malformed Hostnames
vendor_redhat·2026-03-06·CVSS 3.9
CVE-2026-3632 [LOW] CWE-1286 libsoup: libsoup: HTTP Smuggling and Server-Side Request Forgery via Malformed Hostnames
libsoup: libsoup: HTTP Smuggling and Server-Side Request Forgery via Malformed Hostnames
A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP headers. A remote attacker could exploit this to perform HTTP smuggling, where they can send hidden, malicious requests alongside legitimate ones. In certain situations, this could lead to Server-Side Request Forgery (SSRF), enabling an attacker to force the server to make unauthorized requests to other internal or external systems. The impact is low, as SoupServer is not actually used in internet infrastructure.
A flaw was found in libsoup, a library used by applications to send netwo
Debian
CVE-2026-3632: libsoup2.4 - A flaw was found in libsoup, a library used by applications to send network requ...
vendor_debian·2026·CVSS 3.9
CVE-2026-3632 [LOW] CVE-2026-3632: libsoup2.4 - A flaw was found in libsoup, a library used by applications to send network requ...
A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP headers. A remote attacker could exploit this to perform HTTP smuggling, where they can send hidden, malicious requests alongside legitimate ones. In certain situations, this could lead to Server-Side Request Forgery (SSRF), enabling an attacker to force the server to make unauthorized requests to other internal or external systems. The impact is low, as SoupServer is not actually used in internet infrastructure.
Scope: local
bookworm: open
bullseye: open
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-3632 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-3632 [MEDIUM] CVE-2026-3632 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3632 :
Linux Debian vulnerability analysis and mitigation
A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP headers. A remote attacker could exploit this to perform HTTP smuggling, where they can send hidden, malicious requests alongside legitimate ones. In certain situations, this could lead to Server-Side Request Forgery (SSRF), enabling an attacker to force the server to make unauthorized requests to other internal or external systems. The impact is low, as SoupServer is not actually used in internet infrastructure.
Source : NVD
## 5.5
Score
Published March 17, 2026
Severity MEDIUM
CNA Score 3.9
Af
Bugzilla
CVE-2026-3632 libsoup: libsoup: HTTP Smuggling and Server-Side Request Forgery via Malformed Hostnames
bugzilla·2026-03-06·CVSS 5.5
CVE-2026-3632 [MEDIUM] CVE-2026-3632 libsoup: libsoup: HTTP Smuggling and Server-Side Request Forgery via Malformed Hostnames
CVE-2026-3632 libsoup: libsoup: HTTP Smuggling and Server-Side Request Forgery via Malformed Hostnames
When libsoup is used as a client to send a request (a message), soup_message_set_request_host_from_uri() is eventually invoked by soup_session_send_queue_item(). This function takes the host component from a GUri using g_uri_get_host(), and inserts this literally as a Host header value.
Because of Teams/Releng/security#193, this string may contain any character, even ones that are normally not part of a hostname, including \r and \n. Because of this, it is possible to insert CRLF tokens into the Host header value, effectively allowing the insertion of arbitrary headers, and even full requests.
For example, take the following gio cat operation:
gio cat "http://a%0d%0a%0d%0aPOST%20%2ffoo%
2026-03-17
Published