Логотип exploitDog
bind:"CVE-2026-2708"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2026-2708"

Количество 9

Количество 9

ubuntu логотип

CVE-2026-2708

около 1 месяца назад

[libsoup: HTTP/1 request smuggling primitives accepted (CL.CL and TE+CL) in soup_headers_parse()]

EPSS: Низкий
redhat логотип

CVE-2026-2708

около 1 месяца назад

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2026-2708

[libsoup: HTTP/1 request smuggling primitives accepted (CL.CL and TE+CL) in soup_headers_parse()]

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0690-1

29 дней назад

Security update for libsoup

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0689-1

29 дней назад

Security update for libsoup

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0657-1

30 дней назад

Security update for libsoup2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0703-1

28 дней назад

Security update for libsoup

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0834-1

23 дня назад

Security update for libsoup2

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20354-1

15 дней назад

Security update for libsoup2

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-2708

[libsoup: HTTP/1 request smuggling primitives accepted (CL.CL and TE+CL) in soup_headers_parse()]

около 1 месяца назад
redhat логотип
CVE-2026-2708

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values.

CVSS3: 3.7
около 1 месяца назад
debian логотип
CVE-2026-2708

[libsoup: HTTP/1 request smuggling primitives accepted (CL.CL and TE+CL) in soup_headers_parse()]

-
suse-cvrf логотип
SUSE-SU-2026:0690-1

Security update for libsoup

29 дней назад
suse-cvrf логотип
SUSE-SU-2026:0689-1

Security update for libsoup

29 дней назад
suse-cvrf логотип
SUSE-SU-2026:0657-1

Security update for libsoup2

30 дней назад
suse-cvrf логотип
SUSE-SU-2026:0703-1

Security update for libsoup

28 дней назад
suse-cvrf логотип
SUSE-SU-2026:0834-1

Security update for libsoup2

23 дня назад
suse-cvrf логотип
openSUSE-SU-2026:20354-1

Security update for libsoup2

15 дней назад

Уязвимостей на страницу