Количество 6
Количество 6
CVE-2026-85197
(A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the ...)
CVE-2026-85197
A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution.
CVE-2026-85197
A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution.
CVE-2026-85197
Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload
CVE-2026-85197
A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the ...
GHSA-pq26-x6qp-8qr7
A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-85197 (A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the ...) | CVSS3: 7.6 | 0% Низкий | 9 дней назад | |
CVE-2026-85197 A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution. | CVSS3: 7.6 | 0% Низкий | 13 дней назад | |
CVE-2026-85197 A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution. | CVSS3: 7.6 | 0% Низкий | 12 дней назад | |
CVE-2026-85197 Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload | 0% Низкий | 7 дней назад | ||
CVE-2026-85197 A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the ... | CVSS3: 7.6 | 0% Низкий | 12 дней назад | |
GHSA-pq26-x6qp-8qr7 A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution. | CVSS3: 7.6 | 0% Низкий | 12 дней назад |
Уязвимостей на страницу