Skip to main content
EPSS 0.9%top 43%

libsoup security update (CVE-2025-32049)

0
High
Published: 09/25/2026 (09/25/2026, 01:27:35 UTC)
Source: GCVE Database
Product: libsoup

Description

libsoup is an HTTP client/server library for GNOME. It uses GObjects and the glib main loop, to integrate well with GNOME applications, and also has a synchronous API, for use in threaded applications. Security Fix(es): A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to allocate memory and lead to a denial of service (DoS).(CVE-2025-32049) A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS).(CVE-2026-15709) A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as when an HTTP/2 connection encounters window exhaustion or explicit stream resets. A remote, unauthenticated attacker acting as a malicious network peer can trick the connection engine into allocating stream states that are subsequently leaked during cleanup. Over a sustained period, this flaw allows the remote attacker to consume the system's heap allocations incrementally, triggering a denial of service (DoS) through an ultimate Out-of-Memory (OOM) application crash.(CVE-2026-15713) An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-multipart-input-stream.c, which does not adequately restrict or validate the size of incoming multipart boundary strings. When processing a crafted HTTP response containing a malformed or oversized boundary parameter, the internal stream reader reads past the allocated buffer bounds. A remote, unauthenticated attacker can exploit this behavior to cause a service denial (DoS) through application failure or potentially read fragments of unauthorized memory metadata.(CVE-2026-15714) A vulnerability classified as problematic has been found in GNOME libsoup (affected version unknown). CWE is classifying the issue as CWE-93. The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs. This is going to have an impact on integrity. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.(CVE-2026-3633) A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure.(CVE-2026-66339)

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

openEuler:24.03-LTS-SP4more threats →ghsa
libsoup
pkg:rpm/openEuler/libsoup&distro=openEuler-24.03-LTS-SP4
Affected versions
<2.74.3-27.oe2403sp4

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/25/2026, 04:46:27 UTC

Technical Analysis

Libsoup versions before 2.74.3-27.oe2403sp4 contain multiple vulnerabilities: CVE-2025-32049 allows denial of service via large WebSocket messages causing excessive memory allocation; CVE-2026-15709 involves unbounded memory allocation during decompression of permessage-deflate WebSocket frames, enabling a decompression bomb DoS; CVE-2026-15713 is a memory leak in HTTP/2 stream termination that can lead to incremental heap exhaustion and DoS; CVE-2026-15714 is an out-of-bounds read in multipart boundary processing that can cause DoS or memory disclosure; CVE-2026-3633 is a CRLF injection issue impacting data integrity; and CVE-2026-66339 causes information disclosure by leaking proxy credentials after CONNECT tunnels. These vulnerabilities can be exploited remotely without authentication. The CVSS 3.1 base score is 7.5, indicating high severity, primarily due to denial of service impacts. A patch is available to remediate these issues.

Potential Impact

Remote, unauthenticated attackers can exploit these vulnerabilities to cause denial of service through application crashes or memory exhaustion, potentially read unauthorized memory fragments, and disclose proxy credentials to destination servers. The most critical impact is denial of service due to unbounded memory allocation and memory leaks. There is no indication of confidentiality or integrity impact beyond the proxy credential disclosure and the CRLF injection issue affecting integrity.

Mitigation Recommendations

A patch is available for libsoup versions prior to 2.74.3-27.oe2403sp4 that addresses these vulnerabilities. Users should apply the official update to remediate these issues. No additional mitigation actions are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
OESA-2026-4041
Osv Schema Version
1.7.2
Ecosystems
["openEuler:24.03-LTS-SP4"]
Database Specific Severity
High
Cvss Version
3.1

Threat ID: 6ab5fb9af7a7c5410655d1d4

Added to database: 09/25/2026, 04:42:02 UTC

Last enriched: 09/25/2026, 04:46:27 UTC

Last updated: 09/26/2026, 02:50:13 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses