<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:50:27 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:7505 — Important: libsoup3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:7505</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: libsoup3, AlmaLinux:10: libsoup3-devel, AlmaLinux:10: libsoup3-doc&lt;/p&gt;
&lt;p&gt;Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages. libsoup uses the Glib main loop and is designed to work well with GTK applications. This enables GNOME applications to access HTTP servers on the network in a completely asynchronous fashion, very similar to the Gtk+ programming model (a synchronous operation mode is also supported for those who want it), but the SOAP parts were removed long ago.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libsoup: Heap buffer over-read in `skip_insignificant_space` when sniffing content (CVE-2025-2784)
  * libsoup: Out of bounds reads in soup_headers_parse_request() (CVE-2025-32906)
  * libsoup: Denial of service on libsoup through HTTP/2 server (CVE-2025-32908)
  * libsoup: NULL pointer dereference in client when server omits the &amp;#34;nonce&amp;#34; parameter in an Unauthorized response with Digest authentication (CVE-2025-32912)
  * libsoup: OOB Read on libsoup through function &amp;#34;soup_multipart_new_from_message&amp;#34; in soup-multipart.c leads to crash or exit of process (CVE-2025-32914)
  * libsoup: Information disclosure may leads libsoup client sends Authorization header to a different host when being redirected by a server (CVE-2025-46421)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: libsoup3, AlmaLinux:10: libsoup3-devel, AlmaLinux:10: libsoup3-doc&lt;/p&gt;
&lt;p&gt;Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages. libsoup uses the Glib main loop and is designed to work well with GTK applications. This enables GNOME applications to access HTTP servers on the network in a completely asynchronous fashion, very similar to the Gtk+ programming model (a synchronous operation mode is also supported for those who want it), but the SOAP parts were removed long ago.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libsoup: Heap buffer over-read in `skip_insignificant_space` when sniffing content (CVE-2025-2784)
  * libsoup: Out of bounds reads in soup_headers_parse_request() (CVE-2025-32906)
  * libsoup: Denial of service on libsoup through HTTP/2 server (CVE-2025-32908)
  * libsoup: NULL pointer dereference in client when server omits the &amp;#34;nonce&amp;#34; parameter in an Unauthorized response with Digest authentication (CVE-2025-32912)
  * libsoup: OOB Read on libsoup through function &amp;#34;soup_multipart_new_from_message&amp;#34; in soup-multipart.c leads to crash or exit of process (CVE-2025-32914)
  * libsoup: Information disclosure may leads libsoup client sends Authorization header to a different host when being redirected by a server (CVE-2025-46421)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:7505</guid>
    </item>
    <item>
      <title>bdu:2025-07140</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-07140</link>
      <description>bdu:2025-07140</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-07140</guid>
    </item>
    <item>
      <title>EUVD-2026-331255</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-331255</link>
      <description>EUVD-2026-331255</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-331255</guid>
    </item>
    <item>
      <title>fkie_cve-2025-32912</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-32912</link>
      <description>&lt;p&gt;A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-32912</guid>
    </item>
    <item>
      <title>GHSA-hhmv-6rqc-qrc8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hhmv-6rqc-qrc8</link>
      <description>&lt;p&gt;A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hhmv-6rqc-qrc8</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-32912 — Libsoup: null pointer dereference in client when server  omits the "nonce" parameter in an unauthorized response with d…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-32912</link>
      <description>msrc_CVE-2025-32912</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-32912</guid>
    </item>
    <item>
      <title>OESA-2025-1460 — libsoup security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1460</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: libsoup, openEuler:22.03-LTS-SP3: libsoup, openEuler:22.03-LTS-SP4: libsoup, openEuler:24.03-LTS: libsoup, openEuler:24.03-LTS-SP1: libsoup&lt;/p&gt;
&lt;p&gt;libsoup is an HTTP client/server library for GNOME. It uses GObjects and the glib main loop, to integrate well with GNOME applications, and also has a synchronous API, for use in threaded applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.(CVE-2025-32906)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash.(CVE-2025-32909)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.(CVE-2025-32910)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup, which is vulnerable to a use-after-free memory issue not on the heap in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.(CVE-2025-32911)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.(CVE-2025-32912)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup, where the soup_message_headers_get_content_disposition() function is vulnerable to a NULL pointer dereference. This flaw allows a malicious HTTP peer to crash a libsoup client or server that uses th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: libsoup, openEuler:22.03-LTS-SP3: libsoup, openEuler:22.03-LTS-SP4: libsoup, openEuler:24.03-LTS: libsoup, openEuler:24.03-LTS-SP1: libsoup&lt;/p&gt;
&lt;p&gt;libsoup is an HTTP client/server library for GNOME. It uses GObjects and the glib main loop, to integrate well with GNOME applications, and also has a synchronous API, for use in threaded applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.(CVE-2025-32906)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash.(CVE-2025-32909)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.(CVE-2025-32910)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup, which is vulnerable to a use-after-free memory issue not on the heap in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.(CVE-2025-32911)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.(CVE-2025-32912)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup, where the soup_message_headers_get_content_disposition() function is vulnerable to a NULL pointer dereference. This flaw allows a malicious HTTP peer to crash a libsoup client or server that uses th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1460</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15189-1 — libsoup-2_4-1-2.74.3-11.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15189-1</link>
      <description>&lt;p&gt;libsoup-2_4-1-2.74.3-11.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libsoup-2_4-1-2.74.3-11.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15189-1</guid>
    </item>
    <item>
      <title>RHSA-2025:7505 — Red Hat Security Advisory: libsoup3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:7505</link>
      <description>&lt;p&gt;libsoup: Heap buffer over-read in `skip_insignificant_space` when sniffing content libsoup: Out of bounds reads in soup_headers_parse_request() libsoup: Denial of service on libsoup through HTTP/2 server libsoup: NULL pointer dereference in client when server  omits the &amp;#34;nonce&amp;#34; parameter in an Unauthorized response with Digest  authentication libsoup: OOB Read on libsoup through function  &amp;#34;soup_multipart_new_from_message&amp;#34; in soup-multipart.c leads to crash or  exit of process libsoup: Information disclosure may leads libsoup client sends Authorization header to a different host when being redirected by a server&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libsoup: Heap buffer over-read in `skip_insignificant_space` when sniffing content libsoup: Out of bounds reads in soup_headers_parse_request() libsoup: Denial of service on libsoup through HTTP/2 server libsoup: NULL pointer dereference in client when server  omits the &amp;#34;nonce&amp;#34; parameter in an Unauthorized response with Digest  authentication libsoup: OOB Read on libsoup through function  &amp;#34;soup_multipart_new_from_message&amp;#34; in soup-multipart.c leads to crash or  exit of process libsoup: Information disclosure may leads libsoup client sends Authorization header to a different host when being redirected by a server&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:7505</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01794-1 — Security update for libsoup</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01794-1</link>
      <description>&lt;p&gt;Security update for libsoup&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libsoup&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01794-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-32912</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-32912</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: libsoup2.4, Ubuntu:Pro:18.04:LTS: libsoup2.4, Ubuntu:20.04:LTS: libsoup2.4, Ubuntu:22.04:LTS: libsoup2.4, Ubuntu:Pro:22.04:LTS: libsoup3, Ubuntu:24.04:LTS: libsoup2.4, Ubuntu:24.04:LTS: libsoup3&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: libsoup2.4, Ubuntu:Pro:18.04:LTS: libsoup2.4, Ubuntu:20.04:LTS: libsoup2.4, Ubuntu:22.04:LTS: libsoup2.4, Ubuntu:Pro:22.04:LTS: libsoup3, Ubuntu:24.04:LTS: libsoup2.4, Ubuntu:24.04:LTS: libsoup3&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-32912</guid>
    </item>
  </channel>
</rss>
