{"id":"OESA-2026-4040","summary":"libsoup security update","details":"libsoup is an HTTP client/server library for GNOME. It uses GObjects and the glib main loop, to integrate well with GNOME applications, and also has a synchronous API, for use in threaded applications.\r\n\r\nSecurity Fix(es):\n\nA flaw was found in libsoup&apos;s WebSocket implementation when using the permessage-deflate extension. The extension&apos;s decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS).(CVE-2026-15709)\n\nA vulnerability was found in libsoup&apos;s HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as when an HTTP/2 connection encounters window exhaustion or explicit stream resets. A remote, unauthenticated attacker acting as a malicious network peer can trick the connection engine into allocating stream states that are subsequently leaked during cleanup. Over a sustained period, this flaw allows the remote attacker to consume the system&apos;s heap allocations incrementally, triggering a denial of service (DoS) through an ultimate Out-of-Memory (OOM) application crash.(CVE-2026-15713)\n\nAn out-of-bounds read vulnerability was found in libsoup&apos;s multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-multipart-input-stream.c, which does not adequately restrict or validate the size of incoming multipart boundary strings. When processing a crafted HTTP response containing a malformed or oversized boundary parameter, the internal stream reader reads past the allocated buffer bounds. A remote, unauthenticated attacker can exploit this behavior to cause a service denial (DoS) through application failure or potentially read fragments of unauthorized memory metadata.(CVE-2026-15714)\n\nA vulnerability classified as problematic has been found in GNOME libsoup (affected version unknown). CWE is classifying the issue as CWE-93. The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs. This is going to have an impact on integrity. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.(CVE-2026-3633)\n\nA flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure.(CVE-2026-66339)","modified":"2026-09-25T01:45:03.641753737Z","published":"2026-09-25T01:27:35Z","upstream":["CVE-2026-15709","CVE-2026-15713","CVE-2026-15714","CVE-2026-3633","CVE-2026-66339"],"database_specific":{"severity":"High"},"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4040"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15709"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15713"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15714"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3633"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66339"}],"affected":[{"package":{"name":"libsoup","ecosystem":"openEuler:24.03-LTS-SP3","purl":"pkg:rpm/openEuler/libsoup&distro=openEuler-24.03-LTS-SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.74.3-27.oe2403sp3"}]}],"ecosystem_specific":{"x86_64":["libsoup-2.74.3-27.oe2403sp3.x86_64.rpm","libsoup-debuginfo-2.74.3-27.oe2403sp3.x86_64.rpm","libsoup-debugsource-2.74.3-27.oe2403sp3.x86_64.rpm","libsoup-devel-2.74.3-27.oe2403sp3.x86_64.rpm"],"aarch64":["libsoup-2.74.3-27.oe2403sp3.aarch64.rpm","libsoup-debuginfo-2.74.3-27.oe2403sp3.aarch64.rpm","libsoup-debugsource-2.74.3-27.oe2403sp3.aarch64.rpm","libsoup-devel-2.74.3-27.oe2403sp3.aarch64.rpm"],"noarch":["libsoup-help-2.74.3-27.oe2403sp3.noarch.rpm"],"src":["libsoup-2.74.3-27.oe2403sp3.src.rpm"]},"database_specific":{"source":"https://repo.openeuler.org/security/data/osv/OESA-2026-4040.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}