PT-2026-4876 · Gnome+2 · Libsoup+2

Osidb Bzimport

·

Published

2025-12-04

·

Updated

2026-05-15

·

CVE-2026-1467

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions libsoup (affected versions not specified)
Description A flaw exists in libsoup, an HTTP client library, related to CRLF (Carriage Return Line Feed) Injection. This issue occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. An attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allowing them to inject additional HTTP headers or complete HTTP request bodies. This can lead to unintended or unauthorized HTTP requests being forwarded by the proxy, potentially impacting downstream services. CRLF sequences are characters used to denote the end of a line in the HTTP protocol. Improper handling of these sequences can allow an attacker to control the structure of HTTP requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

AZL-76373
AZL-76398
BDU:2026-04951
CVE-2026-1467
OESA-2026-2337
OESA-2026-2338
OESA-2026-2339
OPENSUSE-SU-2026:10276-1
OPENSUSE-SU-2026:10291-1
OPENSUSE-SU-2026:20354-1
OPENSUSE-SU-2026:20384-1
SUSE-SU-2026:0788-1
SUSE-SU-2026:0792-1
SUSE-SU-2026:0796-1
SUSE-SU-2026:0811-1
SUSE-SU-2026:0833-1
SUSE-SU-2026:0834-1
SUSE-SU-2026:20649-1
SUSE-SU-2026:20727-1
SUSE-SU-2026:20752-1
SUSE-SU-2026:20902-1
USN-8020-1

Affected Products

Linuxmint
Ubuntu
Libsoup