{"id":"SUSE-SU-2026:20902-1","summary":"Security update for libsoup","details":"This update for libsoup fixes the following issues:\n\nUpdate to libsoup 3.6.6:\n\n- CVE-2025-12105: heap use-after-free in message queue handling during HTTP/2 read completion (bsc#1252555).\n- CVE-2025-14523: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (bsc#1254876).\n- CVE-2025-32049: Denial of Service attack to websocket server (bsc#1240751).\n- CVE-2026-1467: lack of input sanitization can lead to unintended or unauthorized HTTP requests (bsc#1257398).\n- CVE-2026-1539: proxy authentication credentials leaked via the Proxy-Authorization header when handling HTTP redirects\n  (bsc#1257441).\n- CVE-2026-1760: improper handling of HTTP requests combining certain headers by SoupServer can lead to HTTP request\n  smuggling and potential DoS (bsc#1257597).\n- CVE-2026-2369: Buffer overread due to integer underflow when handling zero-length resources (bsc#1258120).\n- CVE-2026-2443: out-of-bounds read when processing specially crafted HTTP Range headers can lead to heap information\n  disclosure to remote attackers (bsc#1258170).\n- CVE-2026-2708: HTTP request smuggling via duplicate Content-Length headers (bsc#1258508).\n\nChangelog:\n\n- websocket: Fix out-of-bounds read in process_frame\n- Check nulls returned by soup_date_time_new_from_http_string()\n- Numerous fixes to handling of Range headers\n- server: close the connection after responsing a request\ncontaining Content-Length and Transfer-Encoding\n- Use CRLF as line boundary when parsing chunked enconding data\n- websocket: do not accept messages frames after closing due to\nan error\n- Sanitize filename of content disposition header values\n- Always validate the headers value when coming from untrusted\nsource\n- uri-utils: do host validation when checking if a GUri is valid\n- multipart: check length of bytes read\nsoup_filter_input_stream_read_until()\n- message-headers: Reject duplicate Host headers\n- server: null-check soup_date_time_to_string()\n- auth-digest: fix crash in\nsoup_auth_digest_get_protection_space()\n- session: fix 'heap-use-after-free' caused by 'finishing' queue\nitem twice\n- cookies: Avoid expires attribute if date is invalid\n- http1: Set EOF flag once content-length bytes have been read\n- date-utils: Add value checks for date/time parsing\n- multipart: Fix multiple boundry limits\n- Fixed multiple possible memory leaks\n- message-headers: Correct merge of ranges\n- body-input-stream: Correct chunked trailers end detection\n- server-http2: Correctly validate URIs\n- multipart: Fix read out of buffer bounds under\nsoup_multipart_new_from_message()\n- headers: Ensure Request-Line comprises entire first line\n- tests: Fix MSVC build error\n- Fix possible deadlock on init from gmodule usage\n- Updated translations.\n","modified":"2026-04-02T17:24:51.356571Z","published":"2026-03-18T10:01:36Z","related":["CVE-2025-12105","CVE-2025-14523","CVE-2025-32049","CVE-2026-1467","CVE-2026-1539","CVE-2026-1760","CVE-2026-2369","CVE-2026-2443","CVE-2026-2708"],"upstream":["CVE-2025-12105","CVE-2025-14523","CVE-2025-32049","CVE-2026-1467","CVE-2026-1539","CVE-2026-1760","CVE-2026-2369","CVE-2026-2443","CVE-2026-2708"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202620902-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1240751"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252555"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254876"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257398"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257441"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257597"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258120"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258170"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258508"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-12105"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-14523"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-32049"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1467"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1539"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1760"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2369"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2443"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2708"}],"affected":[{"package":{"name":"libsoup","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/libsoup&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.6-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"typelib-1_0-Soup-3_0":"3.6.6-160000.1.1","libsoup-3_0-0":"3.6.6-160000.1.1","libsoup-devel":"3.6.6-160000.1.1","libsoup-lang":"3.6.6-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:20902-1.json"}},{"package":{"name":"libsoup","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/libsoup&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.6-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libsoup-3_0-0":"3.6.6-160000.1.1","libsoup-devel":"3.6.6-160000.1.1","libsoup-lang":"3.6.6-160000.1.1","typelib-1_0-Soup-3_0":"3.6.6-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:20902-1.json"}}],"schema_version":"1.7.5"}