{"id":"CLSA-2026-1771602192","summary":"libsoup: Fix of 8 CVEs","details":"- CVE-2026-1761: fix memory corruption when parsing multipart HTTP responses\n- CVE-2026-0719: fix integer overflow in NTLM authentication when processing\n  excessively long passwords\n- added upstream tests for CVE-2024-52531, CVE-2025-32914, CVE-2025-4948\n- merged CVE-2025-2784 and CVE-2025-32053\n- modified added tests for CVE-2025-46421 as it used 3.x version API\n- skip connection-test","modified":"2026-06-01T00:32:41.671763618Z","published":"2026-02-20T15:43:16Z","upstream":["CVE-2026-1761","CVE-2026-0719","CVE-2024-52531","CVE-2025-32914","CVE-2025-4948","CVE-2025-2784","CVE-2025-32053","CVE-2025-46421"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/tuxcare9.6esu/CLSA-2026-1771602192.html"}],"affected":[{"package":{"name":"libsoup","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/libsoup?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.72.0-10.el9_6.3.tuxcare.els2"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771602192.json"}},{"package":{"name":"libsoup-devel","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/libsoup-devel?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.72.0-10.el9_6.3.tuxcare.els2"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771602192.json"}},{"package":{"name":"libsoup-doc","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/libsoup-doc?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.72.0-10.el9_6.3.tuxcare.els2"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771602192.json"}}],"schema_version":"1.7.5"}