<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T10:32:57.472852+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:18183</id>
    <title>ALSA-2025:18183 — Important: libsoup3 security update</title>
    <updated>2026-10-04T10:32:57.872541+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: libsoup3-doc</p>
<p>Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages. libsoup uses the Glib main loop and is designed to work well with GTK applications. This enables GNOME applications to access HTTP servers on the network in a completely asynchronous fashion, very similar to the Gtk+ programming model (a synchronous operation mode is also supported for those who want it), but the SOAP parts were removed long ago.</p>
<p>Security Fix(es):</p>
<p>* libsoup: Out-of-Bounds Read in Cookie Date Handling of libsoup HTTP Library (CVE-2025-11021)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:18183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-02735</id>
    <title>bdu:2026-02735</title>
    <updated>2026-10-04T10:32:57.872640+00:00</updated>
    <content>bdu:2026-02735</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-02735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0938</id>
    <title>certfr-2025-avi-0938 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-04T10:32:57.872661+00:00</updated>
    <content>certfr-2025-avi-0938</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0938"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-331175</id>
    <title>EUVD-2026-331175</title>
    <updated>2026-10-04T10:32:57.872678+00:00</updated>
    <content>EUVD-2026-331175</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-331175"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-11021</id>
    <title>fkie_cve-2025-11021</title>
    <updated>2026-10-04T10:32:57.872690+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-11021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fjfx-vwp2-gqr8</id>
    <title>GHSA-fjfx-vwp2-gqr8</title>
    <updated>2026-10-04T10:32:57.872714+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fjfx-vwp2-gqr8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-11021</id>
    <title>msrc_CVE-2025-11021 — Libsoup: out-of-bounds read in cookie date handling of libsoup http library</title>
    <updated>2026-10-04T10:32:57.872729+00:00</updated>
    <content>msrc_CVE-2025-11021</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-11021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15633-1</id>
    <title>openSUSE-SU-2025:15633-1 — libsoup-3_0-0-3.6.5-7.1 on GA media</title>
    <updated>2026-10-04T10:32:57.872744+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libsoup-3_0-0-3.6.5-7.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15633-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:18183</id>
    <title>RHSA-2025:18183 — Red Hat Security Advisory: libsoup3 security update</title>
    <updated>2026-10-04T10:32:57.872760+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libsoup: Out-of-Bounds Read in Cookie Date Handling of libsoup HTTP Library</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:18183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:20937-1</id>
    <title>SUSE-SU-2025:20937-1 — Security update for libsoup</title>
    <updated>2026-10-04T10:32:57.872775+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libsoup</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:20937-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-11021</id>
    <title>UBUNTU-CVE-2025-11021</title>
    <updated>2026-10-04T10:32:57.872789+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: libsoup2.4, Ubuntu:Pro:18.04:LTS: libsoup2.4, Ubuntu:Pro:20.04:LTS: libsoup2.4, Ubuntu:22.04:LTS: libsoup2.4, Ubuntu:Pro:22.04:LTS: libsoup3, Ubuntu:24.04:LTS: libsoup2.4, Ubuntu:24.04:LTS: libsoup3, Ubuntu:25.10: libsoup2.4, Ubuntu:25.10: libsoup3, Ubuntu:26.04:LTS: libsoup2.4</p>
<p>A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-11021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2311</id>
    <title>WID-SEC-W-2025-2311 — Red Hat Enterprise Linux (libsoup3): Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-04T10:32:57.872824+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2311"/>
  </entry>
</feed>
