﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
20671	libsoup3-3.6.1	Douglas R. Reno	Douglas R. Reno	"New minor version

It looks like the currency scripts didn't pick this one up. It does have some security fixes in it:

{{{
On 11/9/24 10:45, Alan Coopersmith wrote:
> https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home lists four security
> vulnerabilities reported against libsoup since June 2024, none of which have
> CVE id's listed as being assigned.  (For those not familiar with it, libsoup is
> an HTTP client/server library for the GNOME desktop.)

It appears that Mitre issued CVE id's for the first 3 of these yesterday:

> 1) Request smuggling via stripping of null bytes from the ends of header names
>     https://gitlab.gnome.org/GNOME/libsoup/-/issues/377

https://www.cve.org/CVERecord?id=CVE-2024-52530

> 2) headers: Be more robust against invalid input when parsing params
>     https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/407

https://www.cve.org/CVERecord?id=CVE-2024-52531

> 3) Infinite loop while reading websocket data
>     https://gitlab.gnome.org/GNOME/libsoup/-/issues/391

https://www.cve.org/CVERecord?id=CVE-2024-52532
}}}

Our best bet is to wait until Saturday to do it once the new version is available alongside the rest of GNOME 47.2."	enhancement	closed	elevated	12.3	BOOK	git	medium	fixed		
