cbcvebase.

Debian Libsoup3 vulnerabilities

35 known vulnerabilities affecting debian/libsoup3.

Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM20LOW4

Vulnerabilities

Page 2 of 2
CVE-2025-32053P4MEDIUMCVSS 6.5fixed in libsoup2.4 2.72.0-2+deb11u2 (bullseye)2025
CVE-2025-32053 [MEDIUM] CVE-2025-32053: libsoup2.4 - A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_in... A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead to a heap buffer over-read. Scope: local bookworm: open bullseye: resolved (fixed in 2.72.0-2+deb11u2) trixie: resolved (fixed in 2.74.3-10)
debian
CVE-2026-1467P4MEDIUMCVSS 5.8fixed in libsoup3 3.6.5-8 (forky)2026
CVE-2026-1467 [MEDIUM] CVE-2026-1467: libsoup2.4 - A flaw was found in libsoup, an HTTP client library. This vulnerability, known a... A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allowing them t
debian
CVE-2026-1536P4MEDIUMCVSS 5.8fixed in libsoup3 3.6.5-8 (forky)2026
CVE-2026-1536 [MEDIUM] CVE-2026-1536: libsoup2.4 - A flaw was found in libsoup. An attacker who can control the input for the Conte... A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to HTTP header
debian
CVE-2026-1760P4MEDIUMCVSS 5.3fixed in libsoup3 3.6.5-8 (forky)2026
CVE-2026-1760 [MEDIUM] CVE-2026-1760: libsoup2.4 - A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs... A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding: chunked and Connection: keep-alive headers. A remote, unauthenticated client can exploit this by sending specially crafted requests, causing SoupServer to fail to close the connection as required by RFC 91
debian
CVE-2025-32052P4MEDIUMCVSS 6.5fixed in libsoup2.4 2.72.0-2+deb11u2 (bullseye)2025
CVE-2025-32052 [MEDIUM] CVE-2025-32052: libsoup2.4 - A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may... A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over-read. Scope: local bookworm: open bullseye: resolved (fixed in 2.72.0-2+deb11u2) trixie: resolved (fixed in 2.74.3-10)
debian
CVE-2025-46420P4MEDIUMCVSS 6.5fixed in libsoup2.4 2.74.3-10.1 (trixie)2025
CVE-2025-46420 [MEDIUM] CVE-2025-46420: libsoup2.4 - A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header... A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes. Scope: local bookworm: open bullseye: open trixie: resolved (fixed in 2.74.3-10.1)
debian
CVE-2025-32050P4MEDIUMCVSS 5.9fixed in libsoup2.4 2.72.0-2+deb11u2 (bullseye)2025
CVE-2025-32050 [MEDIUM] CVE-2025-32050: libsoup2.4 - A flaw was found in libsoup. The libsoup append_param_quoted() function may cont... A flaw was found in libsoup. The libsoup append_param_quoted() function may contain an overflow bug resulting in a buffer under-read. Scope: local bookworm: open bullseye: resolved (fixed in 2.72.0-2+deb11u2) trixie: resolved (fixed in 2.74.3-10)
debian
CVE-2025-32907P4MEDIUMCVSS 5.3fixed in libsoup3 3.6.5-2 (forky)2025
CVE-2025-32907 [MEDIUM] CVE-2025-32907: libsoup2.4 - A flaw was found in libsoup. The implementation of HTTP range requests is vulner... A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service. Scope: local bookworm: open bullseye: open t
debian
CVE-2025-32910P4MEDIUMCVSS 6.5fixed in libsoup2.4 2.72.0-2+deb11u2 (bullseye)2025
CVE-2025-32910 [MEDIUM] CVE-2025-32910: libsoup2.4 - A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable... A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash. Scope: local bookworm: open bullseye: resolved (fixed in 2.72.0-2+deb11u2) trixie: resolved (fixed in 2.74.3-10.1)
debian
CVE-2025-32912P4MEDIUMCVSS 6.5fixed in libsoup2.4 2.72.0-2+deb11u2 (bullseye)2025
CVE-2025-32912 [MEDIUM] CVE-2025-32912: libsoup2.4 - A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointe... A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash. Scope: local bookworm: open bullseye: resolved (fixed in 2.72.0-2+deb11u2) trixie: resolved (fixed in 2.74.3-10.1)
debian
CVE-2025-32051P4LOWCVSS 5.9fixed in libsoup3 3.2.3-0+deb12u1 (bookworm)2025
CVE-2025-32051 [MEDIUM] CVE-2025-32051: libsoup2.4 - A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri() function may... A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri() function may crash when processing malformed data URI. This flaw allows an attacker to cause a denial of service (DoS). Scope: local bookworm: resolved bullseye: resolved trixie: resolved
debian
CVE-2025-32909P4MEDIUMCVSS 5.3fixed in libsoup2.4 2.72.0-2+deb11u2 (bullseye)2025
CVE-2025-32909 [MEDIUM] CVE-2025-32909: libsoup2.4 - A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL poin... A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash. Scope: local bookworm: open bullseye: resolved (fixed in 2.72.0-2+deb11u2) trixie: resolved (fixed in 2.74.3-10.1)
debian
CVE-2026-0716P4MEDIUMCVSS 4.8fixed in libsoup3 3.6.5-9 (forky)2026
CVE-2026-0716 [MEDIUM] CVE-2026-0716: libsoup2.4 - A flaw was found in libsoup’s WebSocket frame processing when handling incoming ... A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may
debian
CVE-2025-4476P4MEDIUMCVSS 4.3fixed in libsoup2.4 2.72.0-2+deb11u3 (bullseye)2025
CVE-2025-4476 [MEDIUM] CVE-2025-4476: libsoup2.4 - A denial-of-service vulnerability has been identified in the libsoup HTTP client... A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. A
debian
CVE-2025-4945P4LOWCVSS 3.7fixed in libsoup2.4 2.72.0-2+deb11u3 (bullseye)2025
CVE-2025-4945 [LOW] CVE-2025-4945: libsoup2.4 - A flaw was found in the cookie parsing logic of the libsoup HTTP library, used i... A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persis
debian
Debian Libsoup3 vulnerabilities | cvebase