<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:44:03.488972+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:7436</id>
    <title>ALSA-2025:7436 — Important: libsoup security update</title>
    <updated>2026-10-03T09:44:03.722513+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: libsoup, AlmaLinux:9: libsoup-devel</p>
<p>The libsoup packages provide an HTTP client and server library for GNOME.</p>
<p>Security Fix(es):</p>
<p>* libsoup: Integer overflow in append_param_quoted (CVE-2025-32050)
  * libsoup: Heap buffer overflow in sniff_unknown() (CVE-2025-32052)
  * libsoup: Heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space() (CVE-2025-32053)
  * libsoup: Out of bounds reads in soup_headers_parse_request() (CVE-2025-32906)
  * libsoup: Denial of service in server when client requests a large amount of overlapping ranges with Range header (CVE-2025-32907)
  * libsoup: Double free on soup_message_headers_get_content_disposition() through "soup-message-headers.c" via "params" GHashTable value (CVE-2025-32911)
  * libsoup: NULL pointer dereference in soup_message_headers_get_content_disposition when "filename" parameter is present, but has no value in Content-Disposition header (CVE-2025-32913)
  * libsoup: Information disclosure may leads libsoup client sends Authorization header to a different host when being redirected by a server (CVE-2025-46421)
  * libsoup: Memory leak on soup_header_parse_quality_list() via soup-headers.c (CVE-2025-46420)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:7436"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-04546</id>
    <title>bdu:2025-04546</title>
    <updated>2026-10-03T09:44:03.722602+00:00</updated>
    <content>bdu:2025-04546</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-04546"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-331254</id>
    <title>EUVD-2026-331254</title>
    <updated>2026-10-03T09:44:03.722624+00:00</updated>
    <content>EUVD-2026-331254</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-331254"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-32907</id>
    <title>fkie_cve-2025-32907</title>
    <updated>2026-10-03T09:44:03.722636+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-32907"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7wfq-7p2f-6344</id>
    <title>GHSA-7wfq-7p2f-6344</title>
    <updated>2026-10-03T09:44:03.722659+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7wfq-7p2f-6344"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-32907</id>
    <title>msrc_CVE-2025-32907 — Libsoup: denial of service in server when client requests a large amount of  overlapping ranges with range header</title>
    <updated>2026-10-03T09:44:03.722674+00:00</updated>
    <content>msrc_CVE-2025-32907</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-32907"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1485</id>
    <title>OESA-2025-1485 — libsoup security update</title>
    <updated>2026-10-03T09:44:03.722692+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: libsoup, openEuler:24.03-LTS-SP1: libsoup, openEuler:20.03-LTS-SP4: libsoup, openEuler:22.03-LTS-SP3: libsoup, openEuler:22.03-LTS-SP4: libsoup</p>
<p>libsoup is an HTTP client/server library for GNOME. It uses GObjects and the glib main loop, to integrate well with GNOME applications, and also has a synchronous API, for use in threaded applications.

Security Fix(es):</p>
<p>A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory.(CVE-2025-32907)</p>
<p>A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds.(CVE-2025-32914)</p>
<p>A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.(CVE-2025-46420)</p>
<p>A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.(CVE-2025-46421)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1485"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15043-1</id>
    <title>openSUSE-SU-2025:15043-1 — libsoup-3_0-0-3.6.5-3.1 on GA media</title>
    <updated>2026-10-03T09:44:03.722728+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libsoup-3_0-0-3.6.5-3.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15043-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:4439</id>
    <title>RHSA-2025:4439 — Red Hat Security Advisory: libsoup security update</title>
    <updated>2026-10-03T09:44:03.722749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libsoup: Out of bounds reads in soup_headers_parse_request() libsoup: Denial of service in server when client requests a large amount of  overlapping ranges with Range header libsoup: Double free on  soup_message_headers_get_content_disposition() through  "soup-message-headers.c" via "params" GHashTable value libsoup: NULL pointer dereference in  soup_message_headers_get_content_disposition when "filename" parameter  is present, but has no value in Content-Disposition header libsoup: Memory leak on soup_header_parse_quality_list() via soup-headers.c libsoup: Information disclosure may leads libsoup client sends Authorization header to a different host when being redirected by a server</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:4439"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:1503-1</id>
    <title>SUSE-SU-2025:1503-1 — Security update for libsoup2</title>
    <updated>2026-10-03T09:44:03.722779+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libsoup2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:1503-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-32907</id>
    <title>UBUNTU-CVE-2025-32907</title>
    <updated>2026-10-03T09:44:03.722798+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: libsoup2.4, Ubuntu:Pro:18.04:LTS: libsoup2.4, Ubuntu:Pro:20.04:LTS: libsoup2.4, Ubuntu:22.04:LTS: libsoup2.4, Ubuntu:Pro:22.04:LTS: libsoup3, Ubuntu:24.04:LTS: libsoup2.4, Ubuntu:24.04:LTS: libsoup3, Ubuntu:25.10: libsoup2.4, Ubuntu:25.10: libsoup3, Ubuntu:26.04:LTS: libsoup2.4</p>
<p>A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-32907"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0935</id>
    <title>WID-SEC-W-2025-0935 — Red Hat Enterprise Linux (libsoup): Mehrere Schwachstellen</title>
    <updated>2026-10-03T09:44:03.722832+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service auszulösen, Dateien zu manipulieren oder Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0935"/>
  </entry>
</feed>
