libsoup是GNOME项目的一款GNOME的HTTP客户端/服务器库。 libsoup存在环境问题漏洞,该漏洞源于HTTP/1标头解析逻辑存在请求夹带,soup_message_headers_append_common函数无条件追加标头值,未验证重复或冲突的Content-Length字段。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34003 | 7.8 HIGH | Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-boun |
| CVE-2026-34001 | 7.8 HIGH | Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and pot |
| CVE-2026-33999 | 7.8 HIGH | Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibili |
| CVE-2026-6732 | 6.5 MEDIUM | Libxml2: libxml2: denial of service via crafted xsd-validated document |
| CVE-2025-66286 | 4.7 MEDIUM | Webkitgtk: authorization bypass through webpage::send-request signal handler |
No comments yet