PT-2025-16240 · Libsoup+6 · Libsoup+6
CVE-2025-32908
·
Published
2024-12-01
·
Updated
2026-06-25
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
libsoup (affected versions not specified)
Description
The HTTP/2 server in libsoup contains a flaw where it may not fully validate the values of the pseudo-headers
:scheme, :authority, and :path. This issue occurs within the on frame recv callback() function located in soup-server-message-io-http1.c due to the improper interpretation of input data. A remote attacker could exploit this to cause a denial of service (DoS).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Red Os
Suse
Ubuntu
Libsoup