Use-After-Free Flaw in libsoup for HTTP/2 Server Implementation
CVE-2026-4271

5.3MEDIUM

What is CVE-2026-4271?

An identified flaw in libsoup, a crucial library for managing HTTP requests, encompasses a Use-After-Free vulnerability within its HTTP/2 server functionality. This security weakness allows remote attackers to transmit specially crafted HTTP/2 requests to manipulate authentication processes, resulting in the potential access of previously freed memory. Such behavior may lead to application disruptions and crashes, thereby causing Denial of Service (DoS) conditions, which could impair essential services relying on this library.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank fouzhe for reporting this issue.
.