Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-2443

Опубликовано: 13 фев. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.3

Описание

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.

РелизСтатусПримечание
devel

needs-triage

esm-apps/resolute

needs-triage

esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

needs-triage

noble

needs-triage

questing

needs-triage

resolute

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

3.6.6-1
esm-apps/jammy

needs-triage

jammy

needs-triage

noble

needs-triage

questing

needs-triage

resolute

not-affected

3.6.6-1
upstream

released

3.6.6-1

Показывать по

EPSS

Процентиль: 34%
0.0043
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
4 месяца назад

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.

CVSS3: 5.3
nvd
4 месяца назад

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.

CVSS3: 5.3
msrc
4 месяца назад

Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure

CVSS3: 5.3
debian
4 месяца назад

A flaw was identified in libsoup, a widely used HTTP library in GNOME- ...

CVSS3: 5.3
github
4 месяца назад

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.

EPSS

Процентиль: 34%
0.0043
Низкий

5.3 Medium

CVSS3