PT-2026-23085 · Gnome · Libsoup

Cavid

·

Publicado

2026-01-01

·

Atualizado

2026-04-25

·

CVE-2026-2708

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions libsoup versions 2.4.1-2.74.3 through 2.4.1-2.74.3-17.1 libsoup versions 3.0.0-3.6.6 through 3.0.0-3.6.6-1.1
Description The libsoup library contains flaws related to HTTP/1 request smuggling. Specifically, the soup headers parse() function improperly handles Content-Length (CL.CL) and Transfer-Encoding (TE+CL) header combinations, allowing for request smuggling primitives to be accepted.
Recommendations Update libsoup to version 2.4.1-2.74.3-17.1 or later. Update libsoup to version 3.0.0-3.6.6-1.1 or later.

Correção

HTTP Request/Response Smuggling

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2708
ECHO-A676-B8A7-650C
OPENSUSE-SU-2026:10245-1
OPENSUSE-SU-2026:10246-1
OPENSUSE-SU-2026:20354-1
OPENSUSE-SU-2026:20384-1
SUSE-SU-2026:0657-1
SUSE-SU-2026:0658-1
SUSE-SU-2026:0689-1
SUSE-SU-2026:0690-1
SUSE-SU-2026:0703-1
SUSE-SU-2026:0834-1
SUSE-SU-2026:20529-1
SUSE-SU-2026:20649-1
SUSE-SU-2026:20752-1
SUSE-SU-2026:20902-1

Produtos afetados

Libsoup