Heap Buffer Over-Read Vulnerability in Libsoup Affecting Red Hat
CVE-2026-66337

6.5MEDIUM

What is CVE-2026-66337?

A flaw exists in Libsoup, where an unsigned integer underflow in the soup_filter_input_stream_read_until() function can lead to a heap buffer over-read while processing multipart HTTP responses. This vulnerability could be exploited by a malicious HTTP server that sends specially crafted multipart responses, which may result in client application crashes or exposure of sensitive information residing in heap memory.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges cavid as the original reporter.
.