<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:29:43 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:4560 — Important: libsoup security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:4560</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libsoup, AlmaLinux:8: libsoup-devel&lt;/p&gt;
&lt;p&gt;The libsoup packages provide an HTTP client and server library for GNOME.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libsoup: Integer overflow in append_param_quoted (CVE-2025-32050)
  * libsoup: Heap buffer overflow in sniff_unknown() (CVE-2025-32052)
  * libsoup: Heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space() (CVE-2025-32053)
  * libsoup: Out of bounds reads in soup_headers_parse_request() (CVE-2025-32906)
  * libsoup: Double free on soup_message_headers_get_content_disposition() through &amp;#34;soup-message-headers.c&amp;#34; via &amp;#34;params&amp;#34; GHashTable value (CVE-2025-32911)
  * libsoup: NULL pointer dereference in soup_message_headers_get_content_disposition when &amp;#34;filename&amp;#34; parameter is present, but has no value in Content-Disposition header (CVE-2025-32913)
  * libsoup: Information disclosure may leads libsoup client sends Authorization header to a different host when being redirected by a server (CVE-2025-46421)
  * libsoup: Memory leak on soup_header_parse_quality_list() via soup-headers.c (CVE-2025-46420)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libsoup, AlmaLinux:8: libsoup-devel&lt;/p&gt;
&lt;p&gt;The libsoup packages provide an HTTP client and server library for GNOME.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libsoup: Integer overflow in append_param_quoted (CVE-2025-32050)
  * libsoup: Heap buffer overflow in sniff_unknown() (CVE-2025-32052)
  * libsoup: Heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space() (CVE-2025-32053)
  * libsoup: Out of bounds reads in soup_headers_parse_request() (CVE-2025-32906)
  * libsoup: Double free on soup_message_headers_get_content_disposition() through &amp;#34;soup-message-headers.c&amp;#34; via &amp;#34;params&amp;#34; GHashTable value (CVE-2025-32911)
  * libsoup: NULL pointer dereference in soup_message_headers_get_content_disposition when &amp;#34;filename&amp;#34; parameter is present, but has no value in Content-Disposition header (CVE-2025-32913)
  * libsoup: Information disclosure may leads libsoup client sends Authorization header to a different host when being redirected by a server (CVE-2025-46421)
  * libsoup: Memory leak on soup_header_parse_quality_list() via soup-headers.c (CVE-2025-46420)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:4560</guid>
    </item>
    <item>
      <title>bdu:2025-06114</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-06114</link>
      <description>bdu:2025-06114</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-06114</guid>
    </item>
    <item>
      <title>EUVD-2026-341057</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-341057</link>
      <description>EUVD-2026-341057</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-341057</guid>
    </item>
    <item>
      <title>fkie_cve-2025-46420</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-46420</link>
      <description>&lt;p&gt;A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-46420</guid>
    </item>
    <item>
      <title>GHSA-pv37-78jj-hvqv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pv37-78jj-hvqv</link>
      <description>&lt;p&gt;A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pv37-78jj-hvqv</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-46420 — Libsoup: memory leak on soup_header_parse_quality_list() via soup-headers.c</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-46420</link>
      <description>msrc_CVE-2025-46420</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-46420</guid>
    </item>
    <item>
      <title>OESA-2025-1485 — libsoup security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1485</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: libsoup, openEuler:24.03-LTS-SP1: libsoup, openEuler:20.03-LTS-SP4: libsoup, openEuler:22.03-LTS-SP3: libsoup, openEuler:22.03-LTS-SP4: libsoup&lt;/p&gt;
&lt;p&gt;libsoup is an HTTP client/server library for GNOME. It uses GObjects and the glib main loop, to integrate well with GNOME applications, and also has a synchronous API, for use in threaded applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory.(CVE-2025-32907)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds.(CVE-2025-32914)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.(CVE-2025-46420)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.(CVE-2025-46421)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: libsoup, openEuler:24.03-LTS-SP1: libsoup, openEuler:20.03-LTS-SP4: libsoup, openEuler:22.03-LTS-SP3: libsoup, openEuler:22.03-LTS-SP4: libsoup&lt;/p&gt;
&lt;p&gt;libsoup is an HTTP client/server library for GNOME. It uses GObjects and the glib main loop, to integrate well with GNOME applications, and also has a synchronous API, for use in threaded applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory.(CVE-2025-32907)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds.(CVE-2025-32914)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.(CVE-2025-46420)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.(CVE-2025-46421)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1485</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15044-1 — libsoup-2_4-1-2.74.3-9.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15044-1</link>
      <description>&lt;p&gt;libsoup-2_4-1-2.74.3-9.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libsoup-2_4-1-2.74.3-9.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15044-1</guid>
    </item>
    <item>
      <title>RHSA-2025:4439 — Red Hat Security Advisory: libsoup security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:4439</link>
      <description>&lt;p&gt;libsoup: Out of bounds reads in soup_headers_parse_request() libsoup: Denial of service in server when client requests a large amount of  overlapping ranges with Range header libsoup: Double free on  soup_message_headers_get_content_disposition() through  &amp;#34;soup-message-headers.c&amp;#34; via &amp;#34;params&amp;#34; GHashTable value libsoup: NULL pointer dereference in  soup_message_headers_get_content_disposition when &amp;#34;filename&amp;#34; parameter  is present, but has no value in Content-Disposition header libsoup: Memory leak on soup_header_parse_quality_list() via soup-headers.c libsoup: Information disclosure may leads libsoup client sends Authorization header to a different host when being redirected by a server&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libsoup: Out of bounds reads in soup_headers_parse_request() libsoup: Denial of service in server when client requests a large amount of  overlapping ranges with Range header libsoup: Double free on  soup_message_headers_get_content_disposition() through  &amp;#34;soup-message-headers.c&amp;#34; via &amp;#34;params&amp;#34; GHashTable value libsoup: NULL pointer dereference in  soup_message_headers_get_content_disposition when &amp;#34;filename&amp;#34; parameter  is present, but has no value in Content-Disposition header libsoup: Memory leak on soup_header_parse_quality_list() via soup-headers.c libsoup: Information disclosure may leads libsoup client sends Authorization header to a different host when being redirected by a server&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:4439</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:1503-1 — Security update for libsoup2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:1503-1</link>
      <description>&lt;p&gt;Security update for libsoup2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libsoup2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:1503-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-46420</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-46420</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: libsoup2.4, Ubuntu:Pro:18.04:LTS: libsoup2.4, Ubuntu:20.04:LTS: libsoup2.4, Ubuntu:22.04:LTS: libsoup2.4, Ubuntu:Pro:22.04:LTS: libsoup3, Ubuntu:24.04:LTS: libsoup2.4, Ubuntu:24.04:LTS: libsoup3&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: libsoup2.4, Ubuntu:Pro:18.04:LTS: libsoup2.4, Ubuntu:20.04:LTS: libsoup2.4, Ubuntu:22.04:LTS: libsoup2.4, Ubuntu:Pro:22.04:LTS: libsoup3, Ubuntu:24.04:LTS: libsoup2.4, Ubuntu:24.04:LTS: libsoup3&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-46420</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0935 — Red Hat Enterprise Linux (libsoup): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0935</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service auszulösen, Dateien zu manipulieren oder Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service auszulösen, Dateien zu manipulieren oder Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0935</guid>
    </item>
  </channel>
</rss>
