HTTP Header Injection Vulnerability in GNOME's Libsoup
CVE-2026-3634
3.9LOW
What is CVE-2026-3634?
A vulnerability has been identified in GNOME's Libsoup, where improper input sanitization in the 'soup_message_headers_set_content_type()' function allows attackers to control the content of the Content-Type header. This flaw enables the injection of a Carriage Return Line Feed (CRLF) sequence, which can lead to HTTP header injection and response splitting attacks. As a result, malicious entities may exploit this flaw to manipulate server responses, creating opportunities for further attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Codean Labs for reporting this issue.