5.4mediumMedium
CVE-2026-66338
Gnome Libsoup
A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing differential can be exploited to smuggle HTTP requests.
Exploitation status
- Published references include exploit or proof-of-concept material. There is no confirmation it is being used in real attacks.
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
- To exploit it, no account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 5.4 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N- Weakness
- CWE-444
- Assigned by
- secalert@redhat.com
Dates
- Published
- 2026-07-24
- Last modified
- 2026-08-24
- Sources
- NVD
Affected products
- Gnome Libsoupall versions
- Redhat Enterprise Linux6.0, 7.0, 8.0, 9.0, 10.0
As listed in the NVD configuration data. Not a statement about your estate.