PT-2026-25888 · Libsoup · Libsoup

Published

2026-01-01

·

Updated

2026-03-17

·

CVE-2026-3632

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libsoup (affected versions not specified)
Description libsoup, a library used by applications to send network requests, does not properly validate hostnames, allowing special characters to be injected into HTTP headers. This can be exploited to perform HTTP smuggling, where malicious requests are sent alongside legitimate ones. In certain situations, this could lead to Server-Side Request Forgery (SSRF), enabling an attacker to force the server to make unauthorized requests to other internal or external systems. The impact is considered low, as SoupServer is not widely used in internet infrastructure. The issue involves a CRLF injection in the hostname, leading to request smuggling via URL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04972
CVE-2026-3632
ECHO-CD7E-C6BA-0346

Affected Products

Libsoup