PT-2026-5661 · Libsoup+2 · Libsoup+2

·

CVE-2026-1761

·

Published

2025-11-16

·

Updated

2026-08-31

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:C/A:P
Name of the Vulnerable Software and Affected Versions libsoup (affected versions not specified)
Description A stack-based buffer overflow vulnerability exists in libsoup during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, potentially leading to memory corruption and arbitrary code execution. The issue does not require authentication or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:2182
ALSA-2026:2215
ALSA-2026:2216
ALSA-2026:2410
AZL-76697
AZL-76740
BDU:2026-04958
CVE-2026-1761
ECHO-74B5-8029-1A64
OESA-2026-1405
OESA-2026-1406
OESA-2026-1407
OESA-2026-1408
OESA-2026-1409
OESA-2026-1410
OESA-2026-2698
OESA-2026-2699
OPENSUSE-SU-2026:10139-1
OPENSUSE-SU-2026:10166-1
OPENSUSE-SU-2026:20186-1
OPENSUSE-SU-2026:20283-1
RHSA-2026:1948
RHSA-2026:2005
RHSA-2026:2006
RHSA-2026:2007
RHSA-2026:2008
RHSA-2026:2049
RHSA-2026:2182
RHSA-2026:2214
RHSA-2026:2215
RHSA-2026:2216
RHSA-2026:2396
RHSA-2026:2402
RHSA-2026:2410
RHSA-2026:2512
RHSA-2026:2513
RHSA-2026:2514
RHSA-2026:2528
RHSA-2026:2529
RHSA-2026:2628
SUSE-SU-2026:0418-1
SUSE-SU-2026:0419-1
SUSE-SU-2026:0431-1
SUSE-SU-2026:0497-1
SUSE-SU-2026:0574-1
SUSE-SU-2026:0579-1
SUSE-SU-2026:20238-1
SUSE-SU-2026:20339-1
SUSE-SU-2026:20445-1
SUSE-SU-2026:20649-1

Affected Products

Red Os
Rocky Linux
Libsoup