Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wpfw-5xvc-wq9w

Опубликовано: 26 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the soup_server_disconnect() function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service.

A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the soup_server_disconnect() function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service.

EPSS

Процентиль: 27%
0.00098
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-825

Связанные уязвимости

ubuntu
17 дней назад

[Unknown description]

CVSS3: 6.5
redhat
около 2 месяцев назад

A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service.

debian

Описание отсутствует

EPSS

Процентиль: 27%
0.00098
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-825