Executive brief
A vulnerability in the libsoup networking library can allow attackers to perform "HTTP Request Smuggling" attacks. By sending a specially crafted web request, an attacker can trick a server into misinterpreting where one request ends and the next begins. This can lead to unauthorized access, the bypassing of security controls, or the poisoning of web caches, potentially affecting any application using libsoup in a proxy or backend server configuration.
Technical details
An unsigned-to-signed conversion error exists in the `soup_body_input_stream_read_chunked()` function within `libsoup/http1/soup-body-input-stream.c`. The library parses the HTTP chunk size using `strtoul()` (unsigned) but stores the result in a `goffset` (signed 64-bit) variable. If an attacker provides a chunk size where the most significant bit is set (e.g., ≥ 2^63), the value is interpreted as negative. The state machine treats a non-positive `read_length` as the end of the message body, causing subsequent data on the same keep-alive connection to be interpreted as a new, smuggled HTTP request. This vulnerability is primarily exploitable when libsoup is used in conjunction with another proxy or backend that interprets the chunk size differently.
Affected products
- GNOME libsoup 3.7.0
Timeline
- 2026-01-27: disclosed: Reported via YesWeHack
- 2026-05-29: advisory: CVE published by Red Hat