Security News

Cybersecurity news aggregator

🐧
HIGH Vulnerabilities Ubuntu Security

USN-8523-1: libsoup vulnerabilities

Two vulnerabilities in libsoup (CVE-2026-2369, CVSS 6.5, and CVE-2026-5119, CVSS 5.9) could lead to information disclosure/denial of service via a buffer over-read on zero-length resources, or session hijacking via cookie exposure when tunneling HTTPS through an HTTP proxy. The NVD lists affected versions as gnome libsoup version - and multiple Red Hat Enterprise Linux versions; specific patched version numbers are not provided in the sources.
Read Full Article →

Eric Su and Samuel Dainard discovered that libsoup incorrectly handled content with zero-length resources. An attacker could possibly use this issue to trigger a buffer over-read, resulting in information disclosure or a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-2369) Kona Arctic discovered that libsoup did not properly protect sensitive cookies when establishing HTTPS tunnels through an HTTP proxy. An attacker could possibly use this issue to intercept session cookies, resulting in session hijacking or user impersonation. (CVE-2026-5119)

Share this article