cbcvebase.
CVE-2026-3634
published 2026-03-17

CVE-2026-3634: A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due…

medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for the injection of arbitrary header-value pairs, potentially leading to HTTP header injection and response splitting attacks.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlibsoup2.4
debianlibsoup3
msrcazl3_libsoup_3.4.4-12_on_azure_linux_3.0
msrccbl2_libsoup_3.0.4-12_on_cbl_mariner_2.0
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM