CVE-2026-77680

EUVD-2026-66111
An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix.

CVE-2025-32907 addressed memory amplification when a client repeated the same range many times in a single Range header. Commit 9bb92f7a corrected merge correctness in soup_message_headers_get_ranges_internal() in libsoup/soup-message-headers.c, but the coalescing loop still removes merged ranges using g_array_remove_index() for each coalesced element. Because GArray is contiguous, each mid-array removal performs an O(N) memmove. When many identical satisfiable ranges are supplied (for example bytes=0-0 repeated thousands of times), the loop performs O(N²) work coalescing them into a single range.

The vulnerable path is reachable server-side from handle_partial_get() in libsoup/server/http1/soup-server-message-io-http1.c when a SoupServer handler returns HTTP 200 with a non-empty body. No authentication is required. The number of ranges is bounded only by the maximum request header size (~100 KiB), allowing roughly 25,000 ranges per request. Reporter measurements on libsoup HEAD containing the CVE-2025-32907 fix show ~90 ms single-core CPU per such request at the wire maximum, blocking the server's event loop for that duration.

This is a CPU exhaustion / availability issue only. No memory corruption or information disclosure occurs.

Affected: libsoup versions containing the CVE-2025-32907 fix but not merge request !550.
Fixed upstream: MR !550 merged 2026-08-20, replacing per-element removal with O(N) in-place compaction and rejecting Range headers requesting more than 200 ranges.
Upstream report: https://gitlab.gnome.org/GNOME/libsoup/-/issues/538
Related: CVE-2025-32907
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 25.82%
Debian logo
Debian Releases
Debian Product
Codename
libsoup2.4
bookworm
postponed
trixie
no-dsa
libsoup3
bookworm
postponed
forky
vulnerable
sid
3.8.0-2
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libsoup2.4
bionic
needed
focal
needed
jammy
needed
noble
needed
resolute
needed
xenial
needed
libsoup3
jammy
needed
noble
needed
resolute
needed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
libsoup3
Amazon Linux 2023
0:3.7.2-1.amzn2023
fixed
libsoup3-debuginfo
Amazon Linux 2023
0:3.7.2-1.amzn2023
fixed
libsoup3-debugsource
Amazon Linux 2023
0:3.7.2-1.amzn2023
fixed
libsoup3-devel
Amazon Linux 2023
0:3.7.2-1.amzn2023
fixed
libsoup3-doc
Amazon Linux 2023
0:3.7.2-1.amzn2023
fixed