{"id":"CLSA-2025-1753120992","summary":"libsoup: Fix of 7 CVEs","details":"- CVE-2025-32050: fix overflow in append_param_quoted()\n- CVE-2025-32052: fix heap buffer overflow in soup_content_sniffer_sniff()\n- CVE-2025-32053: fix heap buffer overflow in sniff_feed_or_html()\n- CVE-2025-32907: soup-message-headers: correct merge of ranges\n- CVE-2025-46420: fix leak in soup_header_parse_quality_list()\n- CVE-2025-46421: strip authentication credentails on cross-origin redirect\n- CVE-2025-2784: fix heap buffer over-read when sniffing content via the\n  skip_insight_whitespace() function","modified":"2026-06-01T00:33:26.182953343Z","published":"2025-07-21T18:03:16Z","upstream":["CVE-2025-32050","CVE-2025-32052","CVE-2025-32053","CVE-2025-32907","CVE-2025-46420","CVE-2025-46421","CVE-2025-2784"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/oraclelinux7els/CLSA-2025-1753120992.html"}],"affected":[{"package":{"name":"libsoup","ecosystem":"TuxCare:OracleLinux:7","purl":"pkg:rpm/tuxcare/libsoup?distro=oraclelinux-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.62.2-2.0.1.el7.tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux7els/CLSA-2025-1753120992.json"}},{"package":{"name":"libsoup-devel","ecosystem":"TuxCare:OracleLinux:7","purl":"pkg:rpm/tuxcare/libsoup-devel?distro=oraclelinux-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.62.2-2.0.1.el7.tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux7els/CLSA-2025-1753120992.json"}}],"schema_version":"1.7.5"}