<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:49:47 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:18183 — Important: libsoup3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:18183</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: libsoup3-doc&lt;/p&gt;
&lt;p&gt;Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages. libsoup uses the Glib main loop and is designed to work well with GTK applications. This enables GNOME applications to access HTTP servers on the network in a completely asynchronous fashion, very similar to the Gtk+ programming model (a synchronous operation mode is also supported for those who want it), but the SOAP parts were removed long ago.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libsoup: Out-of-Bounds Read in Cookie Date Handling of libsoup HTTP Library (CVE-2025-11021)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: libsoup3-doc&lt;/p&gt;
&lt;p&gt;Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages. libsoup uses the Glib main loop and is designed to work well with GTK applications. This enables GNOME applications to access HTTP servers on the network in a completely asynchronous fashion, very similar to the Gtk+ programming model (a synchronous operation mode is also supported for those who want it), but the SOAP parts were removed long ago.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libsoup: Out-of-Bounds Read in Cookie Date Handling of libsoup HTTP Library (CVE-2025-11021)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:18183</guid>
    </item>
    <item>
      <title>bdu:2026-02735</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-02735</link>
      <description>bdu:2026-02735</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-02735</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0938 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0938</link>
      <description>certfr-2025-avi-0938</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0938</guid>
    </item>
    <item>
      <title>EUVD-2026-331175</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-331175</link>
      <description>EUVD-2026-331175</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-331175</guid>
    </item>
    <item>
      <title>fkie_cve-2025-11021</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-11021</link>
      <description>&lt;p&gt;A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-11021</guid>
    </item>
    <item>
      <title>GHSA-fjfx-vwp2-gqr8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fjfx-vwp2-gqr8</link>
      <description>&lt;p&gt;A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fjfx-vwp2-gqr8</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-11021 — Libsoup: out-of-bounds read in cookie date handling of libsoup http library</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-11021</link>
      <description>msrc_CVE-2025-11021</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-11021</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15633-1 — libsoup-3_0-0-3.6.5-7.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15633-1</link>
      <description>&lt;p&gt;libsoup-3_0-0-3.6.5-7.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libsoup-3_0-0-3.6.5-7.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15633-1</guid>
    </item>
    <item>
      <title>RHSA-2025:18183 — Red Hat Security Advisory: libsoup3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:18183</link>
      <description>&lt;p&gt;libsoup: Out-of-Bounds Read in Cookie Date Handling of libsoup HTTP Library&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libsoup: Out-of-Bounds Read in Cookie Date Handling of libsoup HTTP Library&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:18183</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:20937-1 — Security update for libsoup</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:20937-1</link>
      <description>&lt;p&gt;Security update for libsoup&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libsoup&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:20937-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-11021</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-11021</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: libsoup2.4, Ubuntu:Pro:18.04:LTS: libsoup2.4, Ubuntu:Pro:20.04:LTS: libsoup2.4, Ubuntu:22.04:LTS: libsoup2.4, Ubuntu:Pro:22.04:LTS: libsoup3, Ubuntu:24.04:LTS: libsoup2.4, Ubuntu:24.04:LTS: libsoup3, Ubuntu:25.10: libsoup2.4, Ubuntu:25.10: libsoup3, Ubuntu:26.04:LTS: libsoup2.4&lt;/p&gt;
&lt;p&gt;A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: libsoup2.4, Ubuntu:Pro:18.04:LTS: libsoup2.4, Ubuntu:Pro:20.04:LTS: libsoup2.4, Ubuntu:22.04:LTS: libsoup2.4, Ubuntu:Pro:22.04:LTS: libsoup3, Ubuntu:24.04:LTS: libsoup2.4, Ubuntu:24.04:LTS: libsoup3, Ubuntu:25.10: libsoup2.4, Ubuntu:25.10: libsoup3, Ubuntu:26.04:LTS: libsoup2.4&lt;/p&gt;
&lt;p&gt;A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of memory contents, potentially exposing sensitive information from the process using libsoup.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-11021</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2311 — Red Hat Enterprise Linux (libsoup3): Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2311</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2311</guid>
    </item>
  </channel>
</rss>
