{"id":"AZL-105543","summary":"CVE-2026-103399 affecting package libsoup 3.4.4-16","details":"A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither drains the declared body bytes nor closes the connection. On a keep-alive connection, those leftover bytes are interpreted as a subsequent HTTP request. A remote, unauthenticated attacker can place a complete HTTP request in the body and cause SoupServer to process that smuggled request, leading to unintended request handling.","modified":"2026-10-05T05:34:30Z","published":"2026-09-30T18:18:16Z","upstream":["CVE-2026-103399"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103399"}],"affected":[{"package":{"name":"libsoup","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libsoup"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.4.4-16"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105543.json"}}],"schema_version":"1.9.0"}