<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:41:44 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:2182 — Important: libsoup3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:2182</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: libsoup3-doc&lt;/p&gt;
&lt;p&gt;Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages. libsoup uses the Glib main loop and is designed to work well with GTK applications. This enables GNOME applications to access HTTP servers on the network in a completely asynchronous fashion, very similar to the Gtk+ programming model (a synchronous operation mode is also supported for those who want it), but the SOAP parts were removed long ago.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libsoup: Signed to Unsigned Conversion Error Leading to Stack-Based Buffer Overflow in libsoup NTLM Authentication (CVE-2026-0719)
  * libsoup: Stack-Based Buffer Overflow in libsoup Multipart Response Parsingmultipart HTTP response (CVE-2026-1761)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: libsoup3-doc&lt;/p&gt;
&lt;p&gt;Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages. libsoup uses the Glib main loop and is designed to work well with GTK applications. This enables GNOME applications to access HTTP servers on the network in a completely asynchronous fashion, very similar to the Gtk+ programming model (a synchronous operation mode is also supported for those who want it), but the SOAP parts were removed long ago.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libsoup: Signed to Unsigned Conversion Error Leading to Stack-Based Buffer Overflow in libsoup NTLM Authentication (CVE-2026-0719)
  * libsoup: Stack-Based Buffer Overflow in libsoup Multipart Response Parsingmultipart HTTP response (CVE-2026-1761)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:2182</guid>
    </item>
    <item>
      <title>bdu:2026-04957</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-04957</link>
      <description>bdu:2026-04957</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-04957</guid>
    </item>
    <item>
      <title>EUVD-2026-337645</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337645</link>
      <description>EUVD-2026-337645</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337645</guid>
    </item>
    <item>
      <title>fkie_cve-2026-0719</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-0719</link>
      <description>&lt;p&gt;A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can overflow due to improper use of signed integers. This results in incorrect memory allocation on the stack, followed by unsafe memory copying. As a result, applications using libsoup may crash unexpectedly, creating a denial-of-service risk.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can overflow due to improper use of signed integers. This results in incorrect memory allocation on the stack, followed by unsafe memory copying. As a result, applications using libsoup may crash unexpectedly, creating a denial-of-service risk.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-0719</guid>
    </item>
    <item>
      <title>GHSA-8x3f-4jvw-ww73</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8x3f-4jvw-ww73</link>
      <description>&lt;p&gt;A flaw was found in libsoup&amp;#39;s NTLM (NT LAN Manager) authentication module. When NTLM authentication is enabled, a local attacker can exploit a stack-based buffer overflow vulnerability in the md4sum() function. This allows the attacker to overwrite adjacent memory, which may result in arbitrary code execution with the privileges of the affected application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libsoup&amp;#39;s NTLM (NT LAN Manager) authentication module. When NTLM authentication is enabled, a local attacker can exploit a stack-based buffer overflow vulnerability in the md4sum() function. This allows the attacker to overwrite adjacent memory, which may result in arbitrary code execution with the privileges of the affected application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8x3f-4jvw-ww73</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-0719 — Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-0719</link>
      <description>msrc_CVE-2026-0719</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-0719</guid>
    </item>
    <item>
      <title>OESA-2026-1323 — libsoup security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1323</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: libsoup&lt;/p&gt;
&lt;p&gt;libsoup is an HTTP client/server library for GNOME. It uses GObjects and the glib main loop, to integrate well with GNOME applications, and also has a synchronous API, for use in threaded applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.(CVE-2025-14523)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup&amp;amp;apos;s NTLM (NT LAN Manager) authentication module. When NTLM authentication is enabled, a local attacker can exploit a stack-based buffer overflow vulnerability in the md4sum() function. This allows the attacker to overwrite adjacent memory, which may result in arbitrary code execution with the privileges of the affected application.(CVE-2026-0719)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: libsoup&lt;/p&gt;
&lt;p&gt;libsoup is an HTTP client/server library for GNOME. It uses GObjects and the glib main loop, to integrate well with GNOME applications, and also has a synchronous API, for use in threaded applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.(CVE-2025-14523)&lt;/p&gt;
&lt;p&gt;A flaw was found in libsoup&amp;amp;apos;s NTLM (NT LAN Manager) authentication module. When NTLM authentication is enabled, a local attacker can exploit a stack-based buffer overflow vulnerability in the md4sum() function. This allows the attacker to overwrite adjacent memory, which may result in arbitrary code execution with the privileges of the affected application.(CVE-2026-0719)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1323</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10040-1 — libsoup-3_0-0-3.6.5-11.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10040-1</link>
      <description>&lt;p&gt;libsoup-3_0-0-3.6.5-11.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libsoup-3_0-0-3.6.5-11.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10040-1</guid>
    </item>
    <item>
      <title>RHSA-2026:1948 — Red Hat Security Advisory: libsoup security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:1948</link>
      <description>&lt;p&gt;libsoup: Signed to Unsigned Conversion Error Leading to Stack-Based Buffer Overflow in libsoup NTLM Authentication libsoup: Stack-Based Buffer Overflow in libsoup Multipart Response Parsingmultipart HTTP response&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libsoup: Signed to Unsigned Conversion Error Leading to Stack-Based Buffer Overflow in libsoup NTLM Authentication libsoup: Stack-Based Buffer Overflow in libsoup Multipart Response Parsingmultipart HTTP response&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:1948</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0151-1 — Security update for libsoup</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0151-1</link>
      <description>&lt;p&gt;Security update for libsoup&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libsoup&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0151-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-0719</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-0719</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: libsoup2.4, Ubuntu:Pro:18.04:LTS: libsoup2.4, Ubuntu:Pro:20.04:LTS: libsoup2.4, Ubuntu:22.04:LTS: libsoup2.4, Ubuntu:Pro:22.04:LTS: libsoup3, Ubuntu:24.04:LTS: libsoup2.4, Ubuntu:24.04:LTS: libsoup3, Ubuntu:25.10: libsoup2.4, Ubuntu:25.10: libsoup3, Ubuntu:26.04:LTS: libsoup3 and 1 more&lt;/p&gt;
&lt;p&gt;A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can overflow due to improper use of signed integers. This results in incorrect memory allocation on the stack, followed by unsafe memory copying. As a result, applications using libsoup may crash unexpectedly, creating a denial-of-service risk.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: libsoup2.4, Ubuntu:Pro:18.04:LTS: libsoup2.4, Ubuntu:Pro:20.04:LTS: libsoup2.4, Ubuntu:22.04:LTS: libsoup2.4, Ubuntu:Pro:22.04:LTS: libsoup3, Ubuntu:24.04:LTS: libsoup2.4, Ubuntu:24.04:LTS: libsoup3, Ubuntu:25.10: libsoup2.4, Ubuntu:25.10: libsoup3, Ubuntu:26.04:LTS: libsoup3 and 1 more&lt;/p&gt;
&lt;p&gt;A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can overflow due to improper use of signed integers. This results in incorrect memory allocation on the stack, followed by unsafe memory copying. As a result, applications using libsoup may crash unexpectedly, creating a denial-of-service risk.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-0719</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0305 — Red Hat Enterprise Linux (libsoup): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0305</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Code auszuführen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Code auszuführen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0305</guid>
    </item>
  </channel>
</rss>
