Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-2708

Опубликовано: 23 апр. 2026
Источник: nvd
CVSS3: 3.7
CVSS3: 5.3
EPSS Низкий

Описание

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gnome:libsoup:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 25%
0.00321
Низкий

3.7 Low

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 3.7
ubuntu
3 месяца назад

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values.

CVSS3: 3.7
redhat
5 месяцев назад

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values.

msrc
3 месяца назад

Libsoup: libsoup: http request smuggling via duplicate content-length headers

CVSS3: 3.7
debian
3 месяца назад

A request smuggling vulnerability exists in libsoup's HTTP/1 header pa ...

CVSS3: 3.7
github
3 месяца назад

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values.

EPSS

Процентиль: 25%
0.00321
Низкий

3.7 Low

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-444