Heap Out-of-Bounds Read in Libsoup Affects GNOME Products
CVE-2026-12548

4.2MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
21 July 2026

What is CVE-2026-12548?

A vulnerability has been identified in libsoup, involving a heap out-of-bounds read flaw. This issue occurs during the parsing of multipart HTTP messages, where an integer type mismatch can lead to the incorrect truncation of the length parameter in the soup_headers_parse() function. Consequently, a remote attacker may exploit this flaw to cause application crashes or potentially access sensitive heap memory contents. Users relying on libsoup should be aware of this vulnerability and consider applying necessary patches to safeguard their applications.

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank linhlhq (Yes We Hack) for reporting this issue.
.