{"id":"ECHO-9de4-e5ae-bd39","summary":"Disputed by upstream. Stateless digest auth is by design; nonce tracking would be a feature addition.\nhttps://gitlab.gnome.org/GNOME/libsoup/-/issues/495\n","modified":"2026-09-15T03:33:44.841591964Z","published":"2026-05-20T08:41:34.038Z","withdrawn":"2026-05-20T08:41:34.038Z","upstream":["CVE-2026-3099"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-3099"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3099"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-3099"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2442232"},{"type":"WEB","url":"https://gitlab.gnome.org/GNOME/libsoup/-/issues/495"}],"affected":[{"package":{"name":"libsoup3","ecosystem":"Echo","purl":"pkg:deb/echo/libsoup3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.6-1+e3"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-9de4-e5ae-bd39.json"}}],"schema_version":"1.9.0"}