<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:24:01.486878+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:8128</id>
    <title>ALSA-2025:8128 — Important: libsoup3 security update</title>
    <updated>2026-10-03T10:24:01.493745+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: libsoup3-doc</p>
<p>Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages. libsoup uses the Glib main loop and is designed to work well with GTK applications. This enables GNOME applications to access HTTP servers on the network in a completely asynchronous fashion, very similar to the Gtk+ programming model (a synchronous operation mode is also supported for those who want it), but the SOAP parts were removed long ago.</p>
<p>Security Fix(es):</p>
<p>* libsoup: Denial of Service attack to websocket server (CVE-2025-32049)
  * libsoup: Denial of service in server when client requests a large amount of overlapping ranges with Range header (CVE-2025-32907)
  * libsoup: Cookie domain validation bypass via uppercase characters in libsoup (CVE-2025-4035)
  * libsoup: Integer Underflow in soup_multipart_new_from_message() Leading to Denial of Service in libsoup (CVE-2025-4948)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:8128"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-10922</id>
    <title>bdu:2025-10922</title>
    <updated>2026-10-03T10:24:01.493815+00:00</updated>
    <content>bdu:2025-10922</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-10922"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-331388</id>
    <title>EUVD-2026-331388</title>
    <updated>2026-10-03T10:24:01.493844+00:00</updated>
    <content>EUVD-2026-331388</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-331388"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-4035</id>
    <title>fkie_cve-2025-4035</title>
    <updated>2026-10-03T10:24:01.493859+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set cookies for domains it does not own, potentially leading to integrity issues such as session fixation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-4035"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9685-44wp-34gm</id>
    <title>GHSA-9685-44wp-34gm</title>
    <updated>2026-10-03T10:24:01.493883+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set cookies for domains it does not own, potentially leading to integrity issues such as session fixation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9685-44wp-34gm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-4035</id>
    <title>msrc_CVE-2025-4035 — Libsoup: cookie domain validation bypass via uppercase characters in libsoup</title>
    <updated>2026-10-03T10:24:01.493900+00:00</updated>
    <content>msrc_CVE-2025-4035</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-4035"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:8128</id>
    <title>RHSA-2025:8128 — Red Hat Security Advisory: libsoup3 security update</title>
    <updated>2026-10-03T10:24:01.493916+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libsoup: Cookie domain validation bypass via uppercase characters in libsoup libsoup: Integer Underflow in soup_multipart_new_from_message() Leading to Denial of Service in libsoup libsoup: Denial of Service attack to websocket server libsoup: Denial of service in server when client requests a large amount of  overlapping ranges with Range header</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:8128"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4035</id>
    <title>UBUNTU-CVE-2025-4035</title>
    <updated>2026-10-03T10:24:01.493935+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: libsoup2.4, Ubuntu:Pro:18.04:LTS: libsoup2.4, Ubuntu:Pro:20.04:LTS: libsoup2.4, Ubuntu:22.04:LTS: libsoup2.4, Ubuntu:Pro:22.04:LTS: libsoup3, Ubuntu:24.04:LTS: libsoup2.4, Ubuntu:24.04:LTS: libsoup3, Ubuntu:25.10: libsoup2.4, Ubuntu:25.10: libsoup3, Ubuntu:26.04:LTS: libsoup3 and 1 more</p>
<p>A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set cookies for domains it does not own, potentially leading to integrity issues such as session fixation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4035"/>
  </entry>
</feed>
