Information on source package libsoup2.4

Available versions

ReleaseVersion
bookworm2.74.3-1+deb12u1
trixie2.74.3-10.1

Open issues

BugbookwormtrixieDescription
CVE-2026-77680vulnerablevulnerable (no DSA)An algorithmic complexity flaw exists in libsoup's HTTP Range header p ...
CVE-2026-77014vulnerablevulnerable (no DSA)A flaw was found in libsoup's SoupServer HTTP Range header processing. ...
CVE-2026-66339vulnerablevulnerable (no DSA)A flaw was found in libsoup. After a CONNECT tunnel is established thr ...
CVE-2026-66338vulnerablevulnerable (no DSA)A flaw was found in libsoup. The chunked transfer encoding parser uses ...
CVE-2026-66337vulnerablevulnerable (no DSA)A flaw was found in libsoup. An unsigned integer underflow in the soup ...
CVE-2026-15714vulnerablevulnerable (no DSA)An out-of-bounds read vulnerability was found in libsoup's multipart p ...
CVE-2026-15713vulnerablevulnerable (no DSA)A vulnerability was found in libsoup's HTTP/2 protocol implementation. ...
CVE-2026-15711vulnerablevulnerable (no DSA)A vulnerability was found in libsoup's WebSocket frame parsing impleme ...
CVE-2026-15709vulnerablevulnerable (no DSA)A flaw was found in libsoup's WebSocket implementation when using the ...
CVE-2026-12548vulnerablevulnerable (no DSA)A heap out-of-bounds read flaw was found in libsoup. When parsing mult ...
CVE-2026-12547vulnerablevulnerable (no DSA)SoupAuthManager caches proxy authentication credentials without scopin ...
CVE-2026-6324vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup. A remote attacker could exploit an unsign ...
CVE-2026-5119vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup. When establishing HTTPS tunnels through a ...
CVE-2026-4271vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup, a library for handling HTTP requests. Thi ...
CVE-2026-3634vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup. An attacker controlling the value used to ...
CVE-2026-3633vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup. A remote attacker, by controlling the met ...
CVE-2026-3632vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup, a library used by applications to send ne ...
CVE-2026-3099vulnerable (no DSA)vulnerable (no DSA)A flaw was found in Libsoup. The server-side digest authentication imp ...
CVE-2026-2708vulnerable (no DSA)vulnerable (no DSA)A request smuggling vulnerability exists in libsoup's HTTP/1 header pa ...
CVE-2026-2443vulnerable (no DSA)vulnerable (no DSA)A flaw was identified in libsoup, a widely used HTTP library in GNOME- ...
CVE-2026-2436vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup's SoupServer. A remote attacker could expl ...
CVE-2026-2369vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup. An integer underflow vulnerability occurs ...
CVE-2026-1801vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup, an HTTP client/server library. This HTTP ...
CVE-2026-1761vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup. This stack-based buffer overflow vulnerab ...
CVE-2026-1760vulnerable (no DSA)vulnerable (no DSA)A flaw was found in SoupServer. This HTTP request smuggling vulnerabil ...
CVE-2026-1539vulnerable (no DSA)vulnerable (no DSA)A flaw was found in the libsoup HTTP library that can cause proxy auth ...
CVE-2026-1536vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup. An attacker who can control the input for ...
CVE-2026-1467vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup, an HTTP client library. This vulnerabilit ...
CVE-2026-0719vulnerable (no DSA)vulnerable (no DSA)A flaw was identified in the NTLM authentication handling of the libso ...
CVE-2026-0716vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup\u2019s WebSocket frame processing when han ...
CVE-2025-46421vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup. When libsoup clients encounter an HTTP re ...
CVE-2025-46420vulnerable (no DSA)fixedA flaw was found in libsoup. It is vulnerable to memory leaks in the s ...
CVE-2025-32914vulnerable (no DSA)fixedA flaw was found in libsoup, where the soup_multipart_new_from_message ...
CVE-2025-32913vulnerable (no DSA)fixedA flaw was found in libsoup, where the soup_message_headers_get_conten ...
CVE-2025-32912vulnerable (no DSA)fixedA flaw was found in libsoup, where SoupAuthDigest is vulnerable to a N ...
CVE-2025-32911vulnerable (no DSA)fixedA use-after-free type vulnerability was found in libsoup, in the soup_ ...
CVE-2025-32910vulnerable (no DSA)fixedA flaw was found in libsoup, where soup_auth_digest_authenticate() is ...
CVE-2025-32909vulnerable (no DSA)fixedA flaw was found in libsoup. SoupContentSniffer may be vulnerable to a ...
CVE-2025-32907vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup. The implementation of HTTP range requests ...
CVE-2025-32906vulnerable (no DSA)fixedA flaw was found in libsoup, where the soup_headers_parse_request() fu ...
CVE-2025-32053vulnerable (no DSA)fixedA flaw was found in libsoup. A vulnerability in sniff_feed_or_html() a ...
CVE-2025-32052vulnerable (no DSA)fixedA flaw was found in libsoup. A vulnerability in the sniff_unknown() fu ...
CVE-2025-32050vulnerable (no DSA)fixedA flaw was found in libsoup. The libsoup append_param_quoted() functio ...
CVE-2025-32049vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup. The SoupWebsocketConnection may accept a ...
CVE-2025-14523vulnerable (no DSA)vulnerable (no DSA)A flaw in libsoup\u2019s HTTP header handling allows multiple Host: he ...
CVE-2025-9901vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup\u2019s caching mechanism, SoupCache, where ...
CVE-2025-4969vulnerable (no DSA)vulnerable (no DSA)A vulnerability was found in the libsoup package. This flaw stems from ...
CVE-2025-4948vulnerable (no DSA)vulnerable (no DSA)A flaw was found in the soup_multipart_new_from_message() function of ...
CVE-2025-4945vulnerable (no DSA)vulnerable (no DSA)A flaw was found in the cookie parsing logic of the libsoup HTTP libra ...
CVE-2025-4476vulnerable (no DSA)vulnerable (no DSA)A denial-of-service vulnerability has been identified in the libsoup H ...
CVE-2025-4035vulnerable (no DSA)vulnerable (no DSA)A flaw was found in libsoup. When handling cookies, libsoup clients mi ...
CVE-2025-2784vulnerable (no DSA)fixedA flaw was found in libsoup. The package is vulnerable to a heap buffe ...

Resolved issues

BugDescription
CVE-2026-15712A heap buffer over-read vulnerability was discovered in libsoup's (ver ...
CVE-2026-12549The fix for CVE-2026-2443 was regressed by a subsequent rework commit ...
CVE-2026-12478The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the i ...
CVE-2025-32908A flaw was found in libsoup. The HTTP/2 server in libsoup may not full ...
CVE-2025-32051A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri() fu ...
CVE-2025-12105A flaw was found in the asynchronous message queue handling of the lib ...
CVE-2024-52532GNOME libsoup before 3.6.1 has an infinite loop, and memory consumptio ...
CVE-2024-52531GNOME libsoup before 3.6.1 allows a buffer overflow in applications th ...
CVE-2024-52530GNOME libsoup before 3.6.0 allows HTTP request smuggling in some confi ...
CVE-2019-17266libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer ove ...
CVE-2018-12910The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows ...
CVE-2017-2885An exploitable stack based buffer overflow vulnerability exists in the ...
CVE-2011-2524Directory traversal vulnerability in soup-uri.c in SoupServer in libso ...

Security announcements

DSA / DLADescription
DLA-4398-1libsoup2.4 - security update
DLA-4140-1libsoup2.4 - security update
DLA-3992-1libsoup2.4 - security update
DLA-1416-1libsoup2.4 - security update
DSA-4241-1libsoup2.4 - security update
DSA-3929-1libsoup2.4 - security update
DSA-2369-1libsoup2.4 - directory traversal

Search for package or bug name: Reporting problems