CVE-2026-2443 – Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure

CVE ID : CVE-2026-2443

Published : Feb. 13, 2026, 11:58 a.m. | 31 minutes ago

Description : A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.

Severity: 5.3 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه