ZeroHour

CVE-2026-3634

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p8
Published
()
Modified
Description

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for the injection of arbitrary header-value pairs, potentially leading to HTTP header injection and response splitting attacks.

Vendors
gnomeredhat
Products
libsoup, enterprise linux
Weakness
CWE-93
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.