Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-3633

Опубликовано: 17 мар. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 3.9

Описание

A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the soup_message_new() function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Carriage Return Line Feed) injection, occurs because the method value is not properly escaped during request line construction, potentially leading to HTTP request injection.

РелизСтатусПримечание
devel

deferred

2026-03-11
esm-apps/resolute

deferred

2026-03-11
esm-infra-legacy/xenial

deferred

2026-03-11
esm-infra/bionic

deferred

2026-03-11
esm-infra/focal

deferred

2026-03-11
esm-infra/xenial

ignored

end of ESM support, was deferred [2026-03-11]
jammy

deferred

2026-03-11
noble

deferred

2026-03-11
questing

ignored

end of life, was deferred [2026-03-11]
resolute

deferred

2026-03-11

Показывать по

РелизСтатусПримечание
devel

deferred

2026-03-11
esm-apps/jammy

deferred

2026-03-11
jammy

deferred

2026-03-11
noble

deferred

2026-03-11
questing

ignored

end of life, was deferred [2026-03-11]
resolute

deferred

2026-03-11
upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 13%
0.00223
Низкий

3.9 Low

CVSS3

Связанные уязвимости

CVSS3: 3.9
redhat
5 месяцев назад

A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Carriage Return Line Feed) injection, occurs because the method value is not properly escaped during request line construction, potentially leading to HTTP request injection.

CVSS3: 3.9
nvd
5 месяцев назад

A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Carriage Return Line Feed) injection, occurs because the method value is not properly escaped during request line construction, potentially leading to HTTP request injection.

msrc
5 месяцев назад

Libsoup: libsoup: header and http request injection via crlf injection

CVSS3: 3.9
debian
5 месяцев назад

A flaw was found in libsoup. A remote attacker, by controlling the met ...

CVSS3: 3.9
github
5 месяцев назад

A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Carriage Return Line Feed) injection, occurs because the method value is not properly escaped during request line construction, potentially leading to HTTP request injection.

EPSS

Процентиль: 13%
0.00223
Низкий

3.9 Low

CVSS3