Opened 8 months ago
Closed 7 months ago
#22811 closed enhancement (fixed)
libsoup3-3.6.6
| Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (7)
comment:1 by , 8 months ago
| Milestone: | 13.1 → 13.0 |
|---|
comment:2 by , 8 months ago
comment:3 by , 8 months ago
I suspect some additional security fixes are probably present in this as well, I'll monitor https://gitlab.gnome.org/Teams/Releng/security/-/wikis/2025 and the 2026 page for libsoup
comment:4 by , 8 months ago
I just dug through everything and here's what I came up with (note that these are additional security fixes on top of the ones we have in our patch)
- CVE-2025-9901: 5.9 Medium. In some cases, libsoup can incorrectly use cached data across different requests, potentially exposing sensitive user information
- CVE-2025-11021: 7.5 High. An out of bounds read can occur when processing cookies with specially crafted expiration dates, leading to unintended disclosure of memory contents and possibly exposing sensitive information from the process using libsoup
- CVE-2025-14523: 8.2 High. Possible request smuggling attacks, cache poisoning, or access control bypasses
- CVE-2026-0716: 4.8 Medium. Unintentional memory disclosure or a crash if using a specific WebSockets configuration
- CVE-2026-1760: 5.3 Medium. HTTP request smuggling attack, which can be performed by an unauthenticated remote attacker
- CVE-2026-1801: 5.3 Medium. HTTP request smuggling attack leading to information disclosure
- CVE-2026-1761: 8.6 High. Stack buffer overflow leading to unauthenticated remote code execution that requires no user interaction.
- CVE-2026-2436: Unknown rating, but: Possible remote code execution or remotely exploitable crash due to a use after free issue (see issue #501 upstream)
- CVE-2026-1536: 5.8 Medium. HTTP header injection or HTTP response splitting without requiring authentication or user interaction.
- CVE-2026-2443: 5.3 Medium. In some specific configurations, this could allow a remote attacker to access portions of server memory beyond the intended response
- CVE-2026-1467: 5.8 Medium. CRLF injection, allowing for additional HTTP headers or complete HTTP request bodies to be injected into a response stream.
- CVE-2026-2369: Unknown on the rating, but we know it is an Integer overflow vulnerability related to a previous vulnerability fix from 3.6.1.
Note that CVE-2026-1539 is fixed upstream but did not make it into the release in time. This one can allow for sensitive proxy credentials to be leaked to other servers.
comment:5 by , 8 months ago
| Priority: | normal → high |
|---|
comment:6 by , 8 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:7 by , 7 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at b0001f44847328d4205cb3adb3de0e911b830043
SA-12.4-101 issued
Note:
See TracTickets
for help on using tickets.

All contents of our security patch should be already merged in this release.