CVE-2026-2708
EUVD-2026-2530623.04.2026, 22:16
A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gnome | libsoup | - |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libsoup-2_4-1 |
| ||||||||||||||||||||
| libsoup-2_4-1-32bit |
| ||||||||||||||||||||
| libsoup-3_0-0 |
| ||||||||||||||||||||
| libsoup-devel |
| ||||||||||||||||||||
| libsoup-lang |
| ||||||||||||||||||||
| libsoup2-devel |
| ||||||||||||||||||||
| libsoup2-lang |
| ||||||||||||||||||||
| typelib-1_0-Soup-2_4 |
| ||||||||||||||||||||
| typelib-1_0-Soup-3_0 |
|
Amazon Linux Releases