Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-2436

Опубликовано: 26 мар. 2026
Источник: nvd
CVSS3: 6.5
CVSS3: 8.2
EPSS Низкий

Описание

A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the soup_server_disconnect() function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gnome:libsoup:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 36%
0.00447
Низкий

6.5 Medium

CVSS3

8.2 High

CVSS3

Дефекты

CWE-825

Связанные уязвимости

CVSS3: 6.5
ubuntu
5 месяцев назад

A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service.

CVSS3: 6.5
redhat
6 месяцев назад

A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service.

CVSS3: 6.5
msrc
4 месяца назад

Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake

CVSS3: 6.5
debian
5 месяцев назад

A flaw was found in libsoup's SoupServer. A remote attacker could expl ...

CVSS3: 6.5
github
5 месяцев назад

A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service.

EPSS

Процентиль: 36%
0.00447
Низкий

6.5 Medium

CVSS3

8.2 High

CVSS3

Дефекты

CWE-825