Bugs fixes in "libsoup3"
| Origin | Bug number | Title | Date fixed |
|---|---|---|---|
| CVE | CVE-2026-85534 | A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the c | 2026-10-07 |
| CVE | CVE-2026-85197 | A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the | 2026-10-07 |
| CVE | CVE-2026-77680 | An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed | 2026-10-07 |
| CVE | CVE-2026-77014 | A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subt | 2026-10-07 |
| CVE | CVE-2026-66339 | A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header | 2026-10-07 |
| CVE | CVE-2026-6324 | A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` fu | 2026-10-07 |
| CVE | CVE-2026-5119 | A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext | 2026-10-07 |
| CVE | CVE-2026-4271 | A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server impleme | 2026-10-07 |
| CVE | CVE-2026-85534 | A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the c | 2026-10-07 |
| CVE | CVE-2026-85197 | A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the | 2026-10-07 |
| CVE | CVE-2026-77680 | An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed | 2026-10-07 |
| CVE | CVE-2026-77014 | A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subt | 2026-10-07 |
| CVE | CVE-2026-66339 | A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header | 2026-10-07 |
| CVE | CVE-2026-6324 | A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` fu | 2026-10-07 |
| CVE | CVE-2026-5119 | A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext | 2026-10-07 |
| CVE | CVE-2026-4271 | A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server impleme | 2026-10-07 |
| CVE | CVE-2026-85534 | A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the c | 2026-10-07 |
| CVE | CVE-2026-85197 | A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the | 2026-10-07 |
| CVE | CVE-2026-77680 | An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed | 2026-10-07 |
| CVE | CVE-2026-77014 | A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subt | 2026-10-07 |
About
-
Send Feedback to @ubuntu_updates