PT-2026-23085 · Gnome · Libsoup

·

CVE-2026-2708

·

Published

2026-01-01

·

Updated

2026-08-30

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions libsoup versions 2.4.1-2.74.3 through 2.4.1-2.74.3-17.1 libsoup versions 3.0.0-3.6.6 through 3.0.0-3.6.6-1.1
Description The libsoup library contains flaws related to HTTP/1 request smuggling. Specifically, the soup headers parse() function improperly handles Content-Length (CL.CL) and Transfer-Encoding (TE+CL) header combinations, allowing for request smuggling primitives to be accepted.
Recommendations Update libsoup to version 2.4.1-2.74.3-17.1 or later. Update libsoup to version 3.0.0-3.6.6-1.1 or later.

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-84683
CVE-2026-2708
ECHO-A676-B8A7-650C
OESA-2026-2666
OESA-2026-2667
OESA-2026-2718
OESA-2026-2719
OESA-2026-3451
OESA-2026-3516
OESA-2026-3517
OPENSUSE-SU-2026:10245-1
OPENSUSE-SU-2026:10246-1
OPENSUSE-SU-2026:20354-1
OPENSUSE-SU-2026:20384-1
SUSE-SU-2026:0657-1
SUSE-SU-2026:0658-1
SUSE-SU-2026:0689-1
SUSE-SU-2026:0690-1
SUSE-SU-2026:0703-1
SUSE-SU-2026:0834-1
SUSE-SU-2026:20529-1
SUSE-SU-2026:20649-1
SUSE-SU-2026:20752-1
SUSE-SU-2026:20902-1

Affected Products

Libsoup