PT-2026-23085 · Gnome · Libsoup

Cavid

·

Published

2026-01-01

·

Updated

2026-04-25

·

CVE-2026-2708

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions libsoup versions 2.4.1-2.74.3 through 2.4.1-2.74.3-17.1 libsoup versions 3.0.0-3.6.6 through 3.0.0-3.6.6-1.1
Description The libsoup library contains flaws related to HTTP/1 request smuggling. Specifically, the soup headers parse() function improperly handles Content-Length (CL.CL) and Transfer-Encoding (TE+CL) header combinations, allowing for request smuggling primitives to be accepted.
Recommendations Update libsoup to version 2.4.1-2.74.3-17.1 or later. Update libsoup to version 3.0.0-3.6.6-1.1 or later.

Fix

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

CVE-2026-2708
OPENSUSE-SU-2026:10245-1
OPENSUSE-SU-2026:10246-1
OPENSUSE-SU-2026:20354-1
OPENSUSE-SU-2026:20384-1
SUSE-SU-2026:0657-1
SUSE-SU-2026:0658-1
SUSE-SU-2026:0689-1
SUSE-SU-2026:0690-1
SUSE-SU-2026:0703-1
SUSE-SU-2026:0834-1
SUSE-SU-2026:20529-1
SUSE-SU-2026:20649-1
SUSE-SU-2026:20752-1
SUSE-SU-2026:20902-1

Affected Products

Libsoup