Threats Tagged 'cve-2026-0716'
View all threats tagged with 'cve-2026-0716'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-0716'
Click on any threat for detailed analysis and mitigation recommendations
0 This security update for libsoup addresses multiple vulnerabilities including an out-of-bounds read in cookie date handling, a stack-based buffer overflow in NTLM authentication, and improper bounds handling that may allow out-of-bounds reads. These issues have been fixed in updated versions of libsoup. The vulnerabilities are rated high severity and patches are available. The update is relevant for various architectures and versions of libsoup used in SUSE and Red Hat Enterprise Linux 10 distributions. Join the discussion | GCVE Database | 01/30/2026, 14:27:53 UTC Added: 06/25/2026, 21:47:12 UTC |
0 This update for libsoup2 fixes the following issues: - CVE-2025-4476: null pointer dereference may lead to denial of service (bsc#1243422). - CVE-2025-14523: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (bsc#1254876). - CVE-2025-32049: Denial of Service attack to websocket server (bsc#1240751). - CVE-2026-0716: improper bounds handling may allow out-of-bounds read (bsc#1256418). - CVE-2026-0719: stack-based buffer overflow in NTLM authentication can lead to arbitrary code execution (bsc#1256399). - CVE-2026-1467: lack of input sanitization can lead to unintended or unauthorized HTTP requests (bsc#1257398). - CVE-2026-1539: proxy authentication credentials leaked via the Proxy-Authorization header when handling HTTP redirects (bsc#1257441). - CVE-2026-1760: improper handling of HTTP requests combining certain headers by SoupServer can lead to HTTP request smuggling and potential DoS (bsc#1257597). - CVE-2026-2369: Buffer overread due to integer underflow when handling zero-length resources (bsc#1258120). - CVE-2026-2443: out-of-bounds read when processing specially crafted HTTP Range headers can lead to heap information disclosure to remote attackers (bsc#1258170). - CVE-2026-2708: HTTP request smuggling via duplicate Content-Length headers (bsc#1258508). Join the discussion | GCVE Database | 01/21/2026, 00:00:00 UTC Added: 06/25/2026, 21:46:50 UTC |
0 A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted. Join the discussion | CVE Database V5 | 01/13/2026, 23:07:06 UTC Added: 01/13/2026, 23:11:30 UTC |
Showing 1 to 3 of 3 results