PT-2026-6059 · Libsoup · Libsoup

·

CVE-2026-1801

·

Published

2025-11-12

·

Updated

2026-06-30

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions libsoup (affected versions not specified)
Description An HTTP Request Smuggling issue exists in libsoup, an HTTP client/server library. The problem stems from non-RFC-compliant parsing within the soup filter input stream read line() function, specifically related to handling chunk headers. The library accepts improperly formatted chunk headers, such as those containing only a line feed (LF) character instead of the required carriage return and line feed (CRLF) sequence. An attacker can exploit this remotely without needing authentication or user interaction by sending crafted chunked requests. This allows the parsing and processing of multiple HTTP requests from a single network message, potentially resulting in information disclosure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-76700
AZL-76736
BDU:2026-04954
CVE-2026-1801
ECHO-47E4-5B68-7DD8
OESA-2026-1449
OESA-2026-2698
OESA-2026-2699
OPENSUSE-SU-2026:10917-1
SUSE-SU-2026:22061-1
SUSE-SU-2026:22071-1
SUSE-SU-2026:2314-1
SUSE-SU-2026:2654-1
SUSE-SU-2026:2670-1
SUSE-SU-2026:2702-1

Affected Products

Libsoup