{"id":"AZL-80226","summary":"CVE-2026-3634 affecting package libsoup 3.4.4-16","details":"A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for the injection of arbitrary header-value pairs, potentially leading to HTTP header injection and response splitting attacks.","modified":"2026-08-28T17:47:53.232555558Z","published":"2026-03-17T10:16:00Z","upstream":["CVE-2026-3634"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3634"}],"affected":[{"package":{"name":"libsoup","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libsoup"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.4.4-16"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-80226.json"}}],"schema_version":"1.9.0"}