Debian Libsoup3 vulnerabilities
35 known vulnerabilities affecting debian/libsoup3.
Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM20LOW4
Vulnerabilities
Page 1 of 2
CVE-2026-1761P2HIGHCVSS 8.6fixed in libsoup3 3.6.5-8 (forky)2026
CVE-2026-1761 [HIGH] CVE-2026-1761: libsoup2.4 - A flaw was found in libsoup. This stack-based buffer overflow vulnerability occu...
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to memory corruption. This issue may result in application crashes or arbitrary code execut
debian
CVE-2025-32911P3CRITICALCVSS 9.0fixed in libsoup2.4 2.72.0-2+deb11u2 (bullseye)2025
CVE-2025-32911 [CRITICAL] CVE-2025-32911: libsoup2.4 - A use-after-free type vulnerability was found in libsoup, in the soup_message_he...
A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.
Scope: local
bookworm: open
bullseye: resolved (fixed in 2.72.0-2+deb11u2)
trixie: resolved (fixed in 2.74.3-10.1)
debian
CVE-2025-14523P3HIGHCVSS 8.2fixed in libsoup3 3.6.5-7 (forky)2025
CVE-2025-14523 [HIGH] CVE-2025-14523: libsoup2.4 - A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a requ...
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepanc
debian
CVE-2026-2369P3MEDIUMCVSS 6.5fixed in libsoup3 3.6.6-1 (forky)2026
CVE-2026-2369 [MEDIUM] CVE-2026-2369: libsoup2.4 - A flaw was found in libsoup. An integer underflow vulnerability occurs when proc...
A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially access sensitive information or cause an application level denial of service.
Scope: local
bookworm: open
bullseye: open
trixie: open
debian
CVE-2025-11021P3HIGHCVSS 7.5fixed in libsoup3 3.6.5-5 (forky)2025
CVE-2025-11021 [HIGH] CVE-2025-11021: libsoup3 - A flaw was found in the cookie date handling logic of the libsoup HTTP library, ...
A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive in
debian
CVE-2025-12105P3LOWCVSS 7.5fixed in libsoup3 3.6.5-6 (forky)2025
CVE-2025-12105 [HIGH] CVE-2025-12105: libsoup2.4 - A flaw was found in the asynchronous message queue handling of the libsoup libra...
A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory acces
debian
CVE-2025-32906P3HIGHCVSS 7.5fixed in libsoup2.4 2.72.0-2+deb11u2 (bullseye)2025
CVE-2025-32906 [HIGH] CVE-2025-32906: libsoup2.4 - A flaw was found in libsoup, where the soup_headers_parse_request() function may...
A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.
Scope: local
bookworm: open
bullseye: resolved (fixed in 2.72.0-2+deb11u2)
trixie: resolved (fixed in 2.74.3-10.1)
debian
CVE-2025-4948P3HIGHCVSS 7.5fixed in libsoup2.4 2.72.0-2+deb11u3 (bullseye)2025
CVE-2025-4948 [HIGH] CVE-2025-4948: libsoup2.4 - A flaw was found in the soup_multipart_new_from_message() function of the libsou...
A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can go wrong, leading to an integer underflow. This
debian
CVE-2025-32914P3HIGHCVSS 7.4fixed in libsoup2.4 2.72.0-2+deb11u2 (bullseye)2025
CVE-2025-32914 [HIGH] CVE-2025-32914: libsoup2.4 - A flaw was found in libsoup, where the soup_multipart_new_from_message() functio...
A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds.
Scope: local
bookworm: open
bullseye: resolved (fixed in 2.72.0-2+deb11u2)
trixie: resolved (fixed in 2.74.3-10.1)
debian
CVE-2024-52530P3HIGHCVSS 7.5fixed in libsoup2.4 2.74.3-1+deb12u1 (bookworm)2024
CVE-2024-52530 [HIGH] CVE-2024-52530: libsoup2.4 - GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations ...
GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.
Scope: local
bookworm: resolved (fixed in 2.74.3-1+deb12u1)
bullseye: resolved (fixed in 2.72.0-2+deb11u1)
trixie
debian
CVE-2024-52532P3HIGHCVSS 7.5fixed in libsoup2.4 2.74.3-1+deb12u1 (bookworm)2024
CVE-2024-52532 [HIGH] CVE-2024-52532: libsoup2.4 - GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during ...
GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.
Scope: local
bookworm: resolved (fixed in 2.74.3-1+deb12u1)
bullseye: resolved (fixed in 2.72.0-2+deb11u1)
trixie: resolved (fixed in 2.74.3-8.1)
debian
CVE-2025-32913P3HIGHCVSS 7.5fixed in libsoup2.4 2.72.0-2+deb11u2 (bullseye)2025
CVE-2025-32913 [HIGH] CVE-2025-32913: libsoup2.4 - A flaw was found in libsoup, where the soup_message_headers_get_content_disposit...
A flaw was found in libsoup, where the soup_message_headers_get_content_disposition() function is vulnerable to a NULL pointer dereference. This flaw allows a malicious HTTP peer to crash a libsoup client or server that uses this function.
Scope: local
bookworm: open
bullseye: resolved (fixed in 2.72.0-2+deb11u2)
trixie: resolved (fixed in 2.74.3-10.1)
debian
CVE-2026-1801P3MEDIUMCVSS 5.3fixed in libsoup3 3.6.5-8 (forky)2026
CVE-2026-1801 [MEDIUM] CVE-2026-1801: libsoup2.4 - A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Sm...
A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk headers, such as lone line feed (LF) characters instead of the required carriage return and line feed (CRLF). A remote attacker can expl
debian
CVE-2025-32908P3LOWCVSS 7.5fixed in libsoup3 3.6.5-2 (forky)2025
CVE-2025-32908 [HIGH] CVE-2025-32908: libsoup2.4 - A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate...
A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of pseudo-headers :scheme, :authority, and :path, which may allow a user to cause a denial of service (DoS).
Scope: local
bookworm: resolved
bullseye: resolved
trixie: resolved
debian
CVE-2025-4969P3MEDIUMCVSS 6.5fixed in libsoup2.4 2.72.0-2+deb11u3 (bullseye)2025
CVE-2025-4969 [MEDIUM] CVE-2025-4969: libsoup2.4 - A vulnerability was found in the libsoup package. This flaw stems from its failu...
A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).
Scope: local
bookworm: open
bu
debian
CVE-2024-52531P3MEDIUMCVSS 6.5fixed in libsoup2.4 2.74.3-1+deb12u1 (bookworm)2024
CVE-2024-52531 [MEDIUM] CVE-2024-52531: libsoup2.4 - GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform...
GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).
Scope: local
bookworm: resolved (fixed in 2.7
debian
CVE-2026-1539P4MEDIUMCVSS 5.8fixed in libsoup3 3.6.5-8 (forky)2026
CVE-2026-1539 [MEDIUM] CVE-2026-1539: libsoup2.4 - A flaw was found in the libsoup HTTP library that can cause proxy authentication...
A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be leaked to thi
debian
CVE-2026-2443P4MEDIUMCVSS 5.3fixed in libsoup3 3.6.6-1 (forky)2026
CVE-2026-2443 [MEDIUM] CVE-2026-2443: libsoup2.4 - A flaw was identified in libsoup, a widely used HTTP library in GNOME-based syst...
A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerabl
debian
CVE-2025-2784P4HIGHCVSS 7.0fixed in libsoup2.4 2.72.0-2+deb11u2 (bullseye)2025
CVE-2025-2784 [HIGH] CVE-2025-2784: libsoup2.4 - A flaw was found in libsoup. The package is vulnerable to a heap buffer over-rea...
A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.
Scope: local
bookworm: open
bullseye: resolved (fixed in 2.72.0-2+deb11u2)
trixie: resolved (fixed in 2.74.3-10)
debian
CVE-2025-46421P4MEDIUMCVSS 6.8fixed in libsoup3 3.2.3-0+deb12u1 (bookworm)2025
CVE-2025-46421 [MEDIUM] CVE-2025-46421: libsoup2.4 - A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, th...
A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.
Scope: local
bookworm: open
bullseye: open
trixie: open
debian
1 / 2Next →