Use-After-Free Flaw in libsoup for HTTP/2 Server Implementation
CVE-2026-4271
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 17 March 2026
What is CVE-2026-4271?
An identified flaw in libsoup, a crucial library for managing HTTP requests, encompasses a Use-After-Free vulnerability within its HTTP/2 server functionality. This security weakness allows remote attackers to transmit specially crafted HTTP/2 requests to manipulate authentication processes, resulting in the potential access of previously freed memory. Such behavior may lead to application disruptions and crashes, thereby causing Denial of Service (DoS) conditions, which could impair essential services relying on this library.
Affected Version(s)
Red Hat Enterprise Linux 10 0:3.6.5-3.el10_1.11
Red Hat Enterprise Linux 10 0:3.6.5-3.el10_2.11
Red Hat Enterprise Linux 10.0 Extended Update Support 0:3.6.5-3.el10_0.15
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved