5.4mediumMedium

CVE-2026-66338

Gnome Libsoup

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing differential can be exploited to smuggle HTTP requests.

Exploitation status

  • Published references include exploit or proof-of-concept material. There is no confirmation it is being used in real attacks.
  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is reachable over a network, without needing local access.
  • For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
  • To exploit it, no account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
5.4 (v3.1)
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-444
Assigned by
secalert@redhat.com

Dates

Published
2026-07-24
Last modified
2026-08-24
Sources
NVD

Affected products

  • Gnome Libsoupall versions
  • Redhat Enterprise Linux6.0, 7.0, 8.0, 9.0, 10.0

As listed in the NVD configuration data. Not a statement about your estate.

References