CVE-2026-3634
published 2026-03-17CVE-2026-3634: A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due…
PriorityP337medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.18%
8.2th percentile
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for the injection of arbitrary header-value pairs, potentially leading to HTTP header injection and response splitting attacks.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsoup2.4 | — | — |
| debian | libsoup3 | — | — |
| msrc | azl3_libsoup_3.4.4-12_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libsoup_3.0.4-12_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian3.9LOW
vendor_msrc3.9LOW
vendor_redhat3.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jx6g-363c-pprr: A flaw was found in libsoup
ghsa_unreviewed·2026-03-17
CVE-2026-3634 [LOW] CWE-93 GHSA-jx6g-363c-pprr: A flaw was found in libsoup
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for the injection of arbitrary header-value pairs, potentially leading to HTTP header injection and response splitting attacks.
OSV
CVE-2026-3634: A flaw was found in libsoup
osv·2026-03-17·CVSS 6.5
CVE-2026-3634 [MEDIUM] CVE-2026-3634: A flaw was found in libsoup
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for the injection of arbitrary header-value pairs, potentially leading to HTTP header injection and response splitting attacks.
Microsoft
Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header
vendor_msrc·2026-03-10·CVSS 3.9
CVE-2026-3634 [LOW] CWE-93 Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header
Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Red Hat
libsoup: libsoup: HTTP header injection and response splitting via CRLF injection in Content-Type header
vendor_redhat·2026-03-06·CVSS 3.9
CVE-2026-3634 [LOW] CWE-93 libsoup: libsoup: HTTP header injection and response splitting via CRLF injection in Content-Type header
libsoup: libsoup: HTTP header injection and response splitting via CRLF injection in Content-Type header
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for the injection of arbitrary header-value pairs, potentially leading to HTTP header injection and response splitting attacks.
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for the injection
Debian
CVE-2026-3634: libsoup2.4 - A flaw was found in libsoup. An attacker controlling the value used to set the C...
vendor_debian·2026·CVSS 3.9
CVE-2026-3634 [LOW] CVE-2026-3634: libsoup2.4 - A flaw was found in libsoup. An attacker controlling the value used to set the C...
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for the injection of arbitrary header-value pairs, potentially leading to HTTP header injection and response splitting attacks.
Scope: local
bookworm: open
bullseye: open
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-3634 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-3634 [MEDIUM] CVE-2026-3634 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3634 :
Linux Debian vulnerability analysis and mitigation
soup_message_headers_set_content_type()
Source : NVD
## 6.5
Score
Published March 17, 2026
Severity MEDIUM
CNA Score 3.9
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libsoup3
libsoup3-devel
Sources
NVD
Debian 11, 12, 13, 14 Severity MEDIUM No Fix Added at: Mar 09, 2026
Echo Severity MEDIUM No Fix Added at: Mar 09, 2026
Red Hat 6, 7, 8, 9, 10 Severity MEDIUM No Fix Added at: Mar 08, 2026
Red Hat 7 Severity MEDIUM Has Fix Added at: Mar 08, 2026
Ubuntu 16.04, 18.04, 20.04, 22.04, 24.04,
Bugzilla
CVE-2026-3634 libsoup: libsoup: HTTP header injection and response splitting via CRLF injection in Content-Type header
bugzilla·2026-03-06·CVSS 6.5
CVE-2026-3634 [MEDIUM] CVE-2026-3634 libsoup: libsoup: HTTP header injection and response splitting via CRLF injection in Content-Type header
CVE-2026-3634 libsoup: libsoup: HTTP header injection and response splitting via CRLF injection in Content-Type header
The soup_message_headers_set_content_type() function sets the Content-Type header value. Internally, it calls soup_message_headers_append_common() to add the new Content-Type value to an accumulating array.
Unlike soup_message_headers_append(), the internal soup_message_headers_append_common() function does not enforce any restrictions on the allowed characters in the header value, allowing the creation of a header whose value contains a CRLF sequence.
Later, when the HTTP request or response is constructed, the header strings are interpreted without further sanitization, resulting in the effective injection of a CRLF sequence, and hence, arbitrary header-value pairs.
A p
2026-03-17
Published