VendorsGNOMElibsoupall versions
Vulnerabilities

GNOME libsoup

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

29CVEs
CVE-2017-2885
An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HTTP request to the vulnerable server to trigger this vulnerability.
Published 2018-04-24 · Modified
9.8EPSS 0.235
CVE-2018-12910
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
Published 2018-07-05 · Modified
9.8EPSS 0.042
CVE-2019-17266
libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.
Published 2019-10-06 · Modified
9.8EPSS 0.028
CVE-2026-2369
Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources
Published 2026-03-19 · Analyzed
9.1EPSS 0.004
CVE-2024-52531
GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).
Published 2024-11-11 · Modified
8.4EPSS 0.007
CVE-2026-2436
Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake
Published 2026-03-26 · Analyzed
8.2EPSS 0.004
CVE-2026-5119
Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment
Published 2026-03-30 · Modified
8.2EPSS 0.003
CVE-2026-4271
Libsoup: libsoup: denial of service via use-after-free in http/2 server
Published 2026-03-17 · Modified
7.5EPSS 0.013
CVE-2024-52532
GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.
Published 2024-11-11 · Modified
7.5EPSS 0.009
CVE-2024-52530
GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.
Published 2024-11-11 · Modified
7.5EPSS 0.008
CVE-2026-3099
Libsoup: libsoup: authentication bypass via digest authentication replay attack
Published 2026-03-12 · Analyzed
7.3EPSS 0.005
CVE-2026-66338
Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked()
Published 2026-07-24 · Analyzed
7.2EPSS 0.003
CVE-2025-2784
Libsoup: heap buffer over-read in `skip_insignificant_space` when sniffing content
Published 2025-04-03 · Modified
7.0EPSS 0.008
CVE-2018-11713
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a WebSocket connection.
Published 2018-06-04 · Modified
6.5EPSS 0.016
CVE-2026-1801
Libsoup: libsoup: http request smuggling via malformed chunk headers
Published 2026-02-03 · Analyzed
6.5EPSS 0.004
CVE-2026-66339
Libsoup: libsoup: proxy credentials leak to destination server via proxy-authorization header in connect tunnels
Published 2026-07-24 · Analyzed
6.5EPSS 0.004
CVE-2026-66337
Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_read_until()
Published 2026-07-24 · Analyzed
6.5EPSS 0.004
CVE-2026-3633
Libsoup: libsoup: header and http request injection via crlf injection
Published 2026-03-17 · Analyzed
6.5EPSS 0.004
CVE-2026-3634
Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header
Published 2026-03-17 · Analyzed
6.5EPSS 0.003
CVE-2026-1467
Libsoup: libsoup: http header injection via specially crafted urls when an http proxy is configured
Published 2026-01-27 · Analyzed
5.8EPSS 0.004
CVE-2026-1536
Libsoup: libsoup: http header injection or response splitting via crlf injection in content-disposition header
Published 2026-01-28 · Analyzed
5.8EPSS 0.003
CVE-2026-1539
Libsoup: libsoup: credential leakage via http redirects
Published 2026-01-28 · Analyzed
5.8EPSS 0.003
CVE-2026-3632
Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
Published 2026-03-17 · Analyzed
5.5EPSS 0.003
CVE-2026-2443
Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure
Published 2026-02-13 · Modified
5.3EPSS 0.004
CVE-2026-2708
Libsoup: libsoup: http request smuggling via duplicate content-length headers
Published 2026-04-23 · Analyzed
5.3EPSS 0.004
CVE-2011-2524
Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI.
Published 2011-08-31 · Modified
5.0EPSS 0.019
CVE-2012-2132
libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.
Published 2012-08-20 · Modified
5.0EPSS 0.016
CVE-2026-12549
Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver
Published 2026-06-22 · Analyzed
4.8EPSS 0.004
CVE-2026-12548
Libsoup: heap out-of-bounds read in libsoup due to integer truncation
Published 2026-07-21 · Analyzed
4.2EPSS 0.003