Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-3634

Опубликовано: 17 мар. 2026
Источник: nvd
CVSS3: 3.9
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the soup_message_headers_set_content_type() function. This vulnerability allows for the injection of arbitrary header-value pairs, potentially leading to HTTP header injection and response splitting attacks.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gnome:libsoup:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 8%
0.00184
Низкий

3.9 Low

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-93

Связанные уязвимости

CVSS3: 3.9
ubuntu
5 месяцев назад

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for the injection of arbitrary header-value pairs, potentially leading to HTTP header injection and response splitting attacks.

CVSS3: 3.9
redhat
5 месяцев назад

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for the injection of arbitrary header-value pairs, potentially leading to HTTP header injection and response splitting attacks.

msrc
5 месяцев назад

Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header

CVSS3: 3.9
debian
5 месяцев назад

A flaw was found in libsoup. An attacker controlling the value used to ...

CVSS3: 3.9
github
5 месяцев назад

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for the injection of arbitrary header-value pairs, potentially leading to HTTP header injection and response splitting attacks.

EPSS

Процентиль: 8%
0.00184
Низкий

3.9 Low

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-93