HTTP Header Injection Vulnerability in GNOME's Libsoup
CVE-2026-3634

3.9LOW

What is CVE-2026-3634?

A vulnerability has been identified in GNOME's Libsoup, where improper input sanitization in the 'soup_message_headers_set_content_type()' function allows attackers to control the content of the Content-Type header. This flaw enables the injection of a Carriage Return Line Feed (CRLF) sequence, which can lead to HTTP header injection and response splitting attacks. As a result, malicious entities may exploit this flaw to manipulate server responses, creating opportunities for further attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Codean Labs for reporting this issue.
.