Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:rpm/redhat/libsoup

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

A moderate severity vulnerability (CVE-2026-15711) exists in the libsoup library used by GNOME, where an oversized control frame in the WebSocket implementation can cause a remote denial of service. Red Hat has issued a security advisory and released updates for Red Hat Enterprise Linux 8 to address this issue.

Join the discussion
0

Two security vulnerabilities have been identified in the libsoup HTTP client and server library for GNOME, affecting Red Hat Enterprise Linux 9. These include a remote denial of service caused by unbounded decompression in the WebSocket permessage-deflate extension (CVE-2026-15709) and a remote denial of service via an oversized control frame protocol violation in WebSocket connections (CVE-2026-15711). Red Hat has released security updates addressing these issues with a moderate severity rating.

Join the discussion
0

This update for libsoup2 fixes the following issues: - CVE-2025-4476: null pointer dereference may lead to denial of service (bsc#1243422). - CVE-2025-14523: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (bsc#1254876). - CVE-2025-32049: Denial of Service attack to websocket server (bsc#1240751). - CVE-2026-0716: improper bounds handling may allow out-of-bounds read (bsc#1256418). - CVE-2026-0719: stack-based buffer overflow in NTLM authentication can lead to arbitrary code execution (bsc#1256399). - CVE-2026-1467: lack of input sanitization can lead to unintended or unauthorized HTTP requests (bsc#1257398). - CVE-2026-1539: proxy authentication credentials leaked via the Proxy-Authorization header when handling HTTP redirects (bsc#1257441). - CVE-2026-1760: improper handling of HTTP requests combining certain headers by SoupServer can lead to HTTP request smuggling and potential DoS (bsc#1257597). - CVE-2026-2369: Buffer overread due to integer underflow when handling zero-length resources (bsc#1258120). - CVE-2026-2443: out-of-bounds read when processing specially crafted HTTP Range headers can lead to heap information disclosure to remote attackers (bsc#1258170). - CVE-2026-2708: HTTP request smuggling via duplicate Content-Length headers (bsc#1258508).

Join the discussion
0

Two security vulnerabilities have been identified in the libsoup HTTP client and server library used in GNOME, affecting Red Hat Enterprise Linux 7 Extended Lifecycle Support. The first vulnerability (CVE-2026-0719) involves a signed to unsigned conversion error that leads to a stack-based buffer overflow in NTLM authentication. The second vulnerability (CVE-2026-1761) is a stack-based buffer overflow in multipart HTTP response parsing. These issues could potentially allow attackers to cause memory corruption. Red Hat has released security updates addressing these vulnerabilities.

Join the discussion

Two stack-based buffer overflow vulnerabilities have been identified in libsoup, affecting the spice-client-win MSI installers for Windows clients distributed with Red Hat Enterprise Linux 8.6 variants. The first vulnerability (CVE-2026-0719) arises from a signed to unsigned conversion error in NTLM authentication, and the second (CVE-2026-1761) involves multipart HTTP response parsing. Red Hat has issued security updates addressing these issues in spice-client-win packages for multiple Red Hat Enterprise Linux 8.6 update services. The vulnerabilities are rated as important by Red Hat Product Security.

Join the discussion
0

The libsoup packages provide an HTTP client and server library for GNOME. Security Fix(es): * libsoup: Signed to Unsigned Conversion Error Leading to Stack-Based Buffer Overflow in libsoup NTLM Authentication (CVE-2026-0719) * libsoup: Stack-Based Buffer Overflow in libsoup Multipart Response Parsingmultipart HTTP response (CVE-2026-1761) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Two security vulnerabilities have been identified in the libsoup HTTP client and server library for GNOME, used in Red Hat Enterprise Linux 9. These include a signed to unsigned conversion error causing a stack-based buffer overflow in NTLM authentication (CVE-2026-0719) and a stack-based buffer overflow in multipart HTTP response parsing (CVE-2026-1761). Red Hat has issued an important security advisory with updates to address these issues. The vulnerabilities are rated as having important security impact, and updated libsoup packages are available for Red Hat Enterprise Linux 9 across multiple architectures.

Join the discussion
0

The libsoup packages provide an HTTP client and server library for GNOME. Security Fix(es): * libsoup: Signed to Unsigned Conversion Error Leading to Stack-Based Buffer Overflow in libsoup NTLM Authentication (CVE-2026-0719) * libsoup: Stack-Based Buffer Overflow in libsoup Multipart Response Parsingmultipart HTTP response (CVE-2026-1761) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Two stack-based buffer overflow vulnerabilities have been identified in the libsoup HTTP client and server library used by GNOME. The first (CVE-2026-0719) involves a signed to unsigned conversion error in NTLM authentication, and the second (CVE-2026-1761) occurs during multipart HTTP response parsing. These vulnerabilities affect Red Hat Enterprise Linux 9.6 Extended Update Support and related packages. Red Hat has issued a security advisory with updated libsoup packages to address these issues.

Join the discussion
0

Two security vulnerabilities have been identified in the libsoup HTTP client and server library used in GNOME, affecting Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions. The first vulnerability (CVE-2026-0719) involves a signed to unsigned conversion error that leads to a stack-based buffer overflow in libsoup NTLM authentication. The second vulnerability (CVE-2026-1761) is a stack-based buffer overflow in libsoup multipart response parsing. Red Hat has released security updates addressing these issues in libsoup version 2.72.0-8.el9_0.9 for multiple architectures. These vulnerabilities are rated as having a high security impact by Red Hat. No known exploits in the wild have been reported at this time.

Join the discussion

Showing 1 to 10 of 32 results

Filters:Package: pkg:rpm/redhat/libsoup
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses