Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-85534

9 дней назад

(A flaw was found in libsoup. When a client sends an HTTP/2 request bod ...)

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2026-85534

13 дней назад

A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-85534

12 дней назад

A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2026-85534

7 дней назад

Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read

EPSS: Низкий
debian логотип

CVE-2026-85534

12 дней назад

A flaw was found in libsoup. When a client sends an HTTP/2 request bod ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-qm5f-xr9c-mm27

12 дней назад

A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-85534

(A flaw was found in libsoup. When a client sends an HTTP/2 request bod ...)

CVSS3: 5.9
0%
Низкий
9 дней назад
redhat логотип
CVE-2026-85534

A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session.

CVSS3: 5.9
0%
Низкий
13 дней назад
nvd логотип
CVE-2026-85534

A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session.

CVSS3: 5.9
0%
Низкий
12 дней назад
msrc логотип
CVE-2026-85534

Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read

0%
Низкий
7 дней назад
debian логотип
CVE-2026-85534

A flaw was found in libsoup. When a client sends an HTTP/2 request bod ...

CVSS3: 5.9
0%
Низкий
12 дней назад
github логотип
GHSA-qm5f-xr9c-mm27

A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session.

CVSS3: 5.9
0%
Низкий
12 дней назад

Уязвимостей на страницу