Heap Buffer Over-Read Vulnerability in Libsoup Affecting Red Hat
CVE-2026-66337
6.5MEDIUM
What is CVE-2026-66337?
A flaw exists in Libsoup, where an unsigned integer underflow in the soup_filter_input_stream_read_until() function can lead to a heap buffer over-read while processing multipart HTTP responses. This vulnerability could be exploited by a malicious HTTP server that sends specially crafted multipart responses, which may result in client application crashes or exposure of sensitive information residing in heap memory.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Upstream acknowledges cavid as the original reporter.