PT-2026-4876 · Gnome+2 · Libsoup+2

·

CVE-2026-1467

·

Published

2025-12-04

·

Updated

2026-05-15

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions libsoup (affected versions not specified)
Description A flaw exists in libsoup, an HTTP client library, related to CRLF (Carriage Return Line Feed) Injection. This issue occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. An attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allowing them to inject additional HTTP headers or complete HTTP request bodies. This can lead to unintended or unauthorized HTTP requests being forwarded by the proxy, potentially impacting downstream services. CRLF sequences are characters used to denote the end of a line in the HTTP protocol. Improper handling of these sequences can allow an attacker to control the structure of HTTP requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-76373
AZL-76398
BDU:2026-04951
CVE-2026-1467
ECHO-C993-31DB-A8BF
OESA-2026-1405
OESA-2026-1406
OESA-2026-1407
OESA-2026-1408
OESA-2026-1409
OESA-2026-1410
OESA-2026-2337
OESA-2026-2338
OESA-2026-2339
OPENSUSE-SU-2026:10276-1
OPENSUSE-SU-2026:10291-1
OPENSUSE-SU-2026:20354-1
OPENSUSE-SU-2026:20384-1
SUSE-SU-2026:0788-1
SUSE-SU-2026:0792-1
SUSE-SU-2026:0796-1
SUSE-SU-2026:0811-1
SUSE-SU-2026:0833-1
SUSE-SU-2026:0834-1
SUSE-SU-2026:20649-1
SUSE-SU-2026:20727-1
SUSE-SU-2026:20752-1
SUSE-SU-2026:20902-1
USN-8020-1

Affected Products

Linuxmint
Ubuntu
Libsoup