CVE-2026-2443 – Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure
CVE ID : CVE-2026-2443
Published : Feb. 13, 2026, 11:58 a.m. | 31 minutes ago
Description : A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more…