Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7wfq-7p2f-6344

Опубликовано: 14 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory.

A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory.

EPSS

Процентиль: 48%
0.00655
Низкий

7.5 High

CVSS3

Дефекты

CWE-1050

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.

CVSS3: 5.3
redhat
больше 1 года назад

A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.

CVSS3: 5.3
nvd
больше 1 года назад

A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.

CVSS3: 5.3
msrc
около 1 года назад

Libsoup: denial of service in server when client requests a large amount of overlapping ranges with range header

CVSS3: 5.3
debian
больше 1 года назад

A flaw was found in libsoup. The implementation of HTTP range requests ...

EPSS

Процентиль: 48%
0.00655
Низкий

7.5 High

CVSS3

Дефекты

CWE-1050