Technology · Gnome
Gnome Libsoup vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 25 vulnerabilities in Gnome Libsoup: 0 in the last 7 days and 14 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-85534, was published on 4 September 2026.
- Last 7 days
- 0
- Last 90 days
- 14
- Critical, all time
- 0
- Exploited in the wild
- 0
About Gnome Libsoup
An HTTP client/server library for GNOME that uses GObjects and the glib main loop.
Latest Gnome Libsoup vulnerabilities
- CVE-2026-85534: libsoup HTTP/2 denial of service via buffer overflow in data callbackmediumCVSS 5.9EPSS 0.5%
- CVE-2026-85197: GNOME libsoup heap use-after-free in HTTP/2 clienthighCVSS 7.6EPSS 0.4%
- CVE-2026-77680: libsoup HTTP Range header algorithmic complexity denial of servicemediumCVSS 5.3EPSS 0.6%
- CVE-2026-77014: libsoup integer truncation in HTTP Range processingmediumCVSS 5.3EPSS 0.4%
- CVE-2026-66338: GNOME libsoup HTTP request smuggling in chunked transfer encoding parsermediumCVSS 5.4
- CVE-2026-66337: GNOME libsoup heap buffer over-read in soup_filter_input_stream_read_untilmediumCVSS 6.5
- CVE-2026-12548: GNOME libsoup heap out-of-bounds read in multipart HTTP parsingmediumCVSS 4.2
- CVE-2026-12547: GNOME libsoup information disclosure in SoupAuthManager proxy credential handlinglowCVSS 3.4
- CVE-2026-15714: GNOME libsoup out-of-bounds read in multipart boundary processingmediumCVSS 6.5
- CVE-2026-15713: libsoup memory leak in HTTP/2 stream terminationmediumCVSS 5.9
- CVE-2026-15711: GNOME libsoup denial of service via oversized WebSocket control framehighCVSS 7.5
- CVE-2026-15709: libsoup WebSocket unbounded decompression memory exhaustionhighCVSS 7.5
- CVE-2026-15712: GNOME libsoup heap buffer over-read in HTTP/2 GOAWAY frame parsingmediumCVSS 5.9
- CVE-2026-12478: GNOME libsoup out-of-bounds read in WebSocket frame processingmediumCVSS 4.8
- CVE-2026-12549: GNOME libsoup buffer access error in Range header parsingmediumCVSS 4.8
- CVE-2026-6324: GNOME libsoup HTTP request smuggling in soup_body_input_stream_read_chunkedmediumCVSS 4.8
- CVE-2026-5119: GNOME libsoup cleartext cookie disclosure in HTTPS proxy tunnelingmediumCVSS 5.9EPSS 0.0%
- CVE-2026-4271: GNOME libsoup use-after-free in HTTP/2 server implementationmediumCVSS 5.3EPSS 0.9%
- CVE-2026-1761: GNOME libsoup stack-based buffer overflow in multipart response parsinghighCVSS 8.6EPSS 0.9%
- CVE-2026-0716: libsoup WebSocket out-of-bounds read in frame processingmediumCVSS 4.8EPSS 0.4%
- CVE-2026-0719: GNOME libsoup stack buffer overflow in NTLM authenticationhighCVSS 8.6EPSS 0.6%
- CVE-2025-14523: GNOME libsoup HTTP request smuggling via duplicate Host headershighCVSS 8.2EPSS 0.5%
- CVE-2025-12105: GNOME libsoup use-after-free in message queue handlinghighCVSS 7.5EPSS 0.4%
- CVE-2025-11021: GNOME libsoup out-of-bounds read in cookie date handlinghighCVSS 7.5EPSS 0.6%
- CVE-2025-9901: GNOME libsoup information disclosure in SoupCache via HTTP Vary headermediumCVSS 5.9EPSS 0.4%
Most severe Gnome Libsoup vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-1761: GNOME libsoup stack-based buffer overflow in multipart response parsinghighCVSS 8.6EPSS 0.9%
- CVE-2026-0719: GNOME libsoup stack buffer overflow in NTLM authenticationhighCVSS 8.6EPSS 0.6%
- CVE-2025-14523: GNOME libsoup HTTP request smuggling via duplicate Host headershighCVSS 8.2EPSS 0.5%
- CVE-2026-85197: GNOME libsoup heap use-after-free in HTTP/2 clienthighCVSS 7.6EPSS 0.4%
- CVE-2025-11021: GNOME libsoup out-of-bounds read in cookie date handlinghighCVSS 7.5EPSS 0.6%
- CVE-2025-12105: GNOME libsoup use-after-free in message queue handlinghighCVSS 7.5EPSS 0.4%
- CVE-2026-15711: GNOME libsoup denial of service via oversized WebSocket control framehighCVSS 7.5
- CVE-2026-15709: libsoup WebSocket unbounded decompression memory exhaustionhighCVSS 7.5
- CVE-2026-66337: GNOME libsoup heap buffer over-read in soup_filter_input_stream_read_untilmediumCVSS 6.5
- CVE-2026-15714: GNOME libsoup out-of-bounds read in multipart boundary processingmediumCVSS 6.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 6 | 0 | |
| 20 Jul 2026 | 4 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 2 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/libsoup.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Gnome Libsoup vulnerabilities", https://junglewise.ai/threats/technologies/libsoup, 26 September 2026.