Known Vulnerabilities for Libsoup by Gnome

Listed below are 10 of the newest known vulnerabilities associated with "Libsoup" by "Gnome".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-85534 json A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buf... Not Provided 2026-09-04 2026-09-04
CVE-2026-85197 json A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-fr... Not Provided 2026-09-04 2026-09-04
CVE-2026-77680 json An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. ... Not Provided 2026-08-25 2026-08-26
CVE-2026-77014 json A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c... Not Provided 2026-08-20 2026-08-25
CVE-2026-66339 json A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Pr... Not Provided 2026-07-24 2026-07-28
CVE-2026-66338 json A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that sil... Not Provided 2026-07-24 2026-07-27
CVE-2026-66337 json A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a hea... Not Provided 2026-07-24 2026-07-27
CVE-2026-15714 json An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multip... Not Provided 2026-07-14 2026-07-15
CVE-2026-15713 json A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory context ... Not Provided 2026-07-14 2026-07-15
CVE-2026-15712 json A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking... Not Provided 2026-07-14 2026-07-14

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationGnomeLibsoup2.68.2
ApplicationGnomeLibsoup2.68.1
ApplicationGnomeLibsoup2.68.0
ApplicationGnomeLibsoup2.67.93
ApplicationGnomeLibsoup2.67.92
ApplicationGnomeLibsoup2.67.91
ApplicationGnomeLibsoup2.67.90
ApplicationGnomeLibsoup2.67.3
ApplicationGnomeLibsoup2.67.2
ApplicationGnomeLibsoup2.67.1
ApplicationGnomeLibsoup2.66.4
ApplicationGnomeLibsoup2.66.3
ApplicationGnomeLibsoup2.66.2
ApplicationGnomeLibsoup2.66.1
ApplicationGnomeLibsoup2.66.0
ApplicationGnomeLibsoup2.66
ApplicationGnomeLibsoup2.65.92
ApplicationGnomeLibsoup2.65.91
ApplicationGnomeLibsoup2.65.90
ApplicationGnomeLibsoup2.65.2

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report