{"schema_version":1,"title":"Gnome Libsoup vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 25 vulnerabilities in Gnome Libsoup: 0 in the last 7 days and 14 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-85534, was published on 4 September 2026.","url":"https://junglewise.ai/threats/technologies/libsoup","json_url":"https://junglewise.ai/threats/technologies/libsoup.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/libsoup","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":8,"all_time":25,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":2,"last_90_days":14,"last_365_days":23},"latest":[{"cve":"CVE-2026-85534","cvss":5.9,"epss":0.0053,"slug":"cve-2026-85534-libsoup-http-2-denial-of-service-via-buffer-overflow-in-data","title":"libsoup HTTP/2 denial of service via buffer overflow in data callback","severity":"medium","exploited":false,"published_at":"2026-09-04T11:17:19.627+00:00","url":"https://junglewise.ai/threats/cve-2026-85534-libsoup-http-2-denial-of-service-via-buffer-overflow-in-data"},{"cve":"CVE-2026-85197","cvss":7.6,"epss":0.0041,"slug":"cve-2026-85197-gnome-libsoup-heap-use-after-free-in-http-2-client","title":"GNOME libsoup heap use-after-free in HTTP/2 client","severity":"high","exploited":false,"published_at":"2026-09-04T08:17:16.677+00:00","url":"https://junglewise.ai/threats/cve-2026-85197-gnome-libsoup-heap-use-after-free-in-http-2-client"},{"cve":"CVE-2026-77680","cvss":5.3,"epss":0.0062,"slug":"cve-2026-77680-libsoup-http-range-header-algorithmic-complexity-denial-of","title":"libsoup HTTP Range header algorithmic complexity denial of service","severity":"medium","exploited":false,"published_at":"2026-08-25T21:17:46.243+00:00","url":"https://junglewise.ai/threats/cve-2026-77680-libsoup-http-range-header-algorithmic-complexity-denial-of"},{"cve":"CVE-2026-77014","cvss":5.3,"epss":0.004,"slug":"cve-2026-77014-libsoup-integer-truncation-in-http-range-processing","title":"libsoup integer truncation in HTTP Range processing","severity":"medium","exploited":false,"published_at":"2026-08-20T09:16:48.167+00:00","url":"https://junglewise.ai/threats/cve-2026-77014-libsoup-integer-truncation-in-http-range-processing"},{"cve":"CVE-2026-66338","cvss":5.4,"slug":"cve-2026-66338-gnome-libsoup-http-request-smuggling-in-chunked-transfer-encoding","title":"GNOME libsoup HTTP request smuggling in chunked transfer encoding parser","severity":"medium","exploited":false,"published_at":"2026-07-24T23:16:52.04+00:00","url":"https://junglewise.ai/threats/cve-2026-66338-gnome-libsoup-http-request-smuggling-in-chunked-transfer-encoding"},{"cve":"CVE-2026-66337","cvss":6.5,"slug":"cve-2026-66337-gnome-libsoup-heap-buffer-over-read-in-soup-filter-input-stream","title":"GNOME libsoup heap buffer over-read in soup_filter_input_stream_read_until","severity":"medium","exploited":false,"published_at":"2026-07-24T23:16:51.76+00:00","url":"https://junglewise.ai/threats/cve-2026-66337-gnome-libsoup-heap-buffer-over-read-in-soup-filter-input-stream"},{"cve":"CVE-2026-12548","cvss":4.2,"slug":"cve-2026-12548-gnome-libsoup-heap-out-of-bounds-read-in-multipart-http-parsing","title":"GNOME libsoup heap out-of-bounds read in multipart HTTP parsing","severity":"medium","exploited":false,"published_at":"2026-07-21T19:17:09.44+00:00","url":"https://junglewise.ai/threats/cve-2026-12548-gnome-libsoup-heap-out-of-bounds-read-in-multipart-http-parsing"},{"cve":"CVE-2026-12547","cvss":3.4,"slug":"cve-2026-12547-gnome-libsoup-information-disclosure-in-soupauthmanager-proxy","title":"GNOME libsoup information disclosure in SoupAuthManager proxy credential handling","severity":"low","exploited":false,"published_at":"2026-07-21T19:17:09.303+00:00","url":"https://junglewise.ai/threats/cve-2026-12547-gnome-libsoup-information-disclosure-in-soupauthmanager-proxy"},{"cve":"CVE-2026-15714","cvss":6.5,"slug":"cve-2026-15714-gnome-libsoup-out-of-bounds-read-in-multipart-boundary-processing","title":"GNOME libsoup out-of-bounds read in multipart boundary processing","severity":"medium","exploited":false,"published_at":"2026-07-14T20:16:57.56+00:00","url":"https://junglewise.ai/threats/cve-2026-15714-gnome-libsoup-out-of-bounds-read-in-multipart-boundary-processing"},{"cve":"CVE-2026-15713","cvss":5.9,"slug":"cve-2026-15713-libsoup-memory-leak-in-http-2-stream-termination","title":"libsoup memory leak in HTTP/2 stream termination","severity":"medium","exploited":false,"published_at":"2026-07-14T20:16:57.43+00:00","url":"https://junglewise.ai/threats/cve-2026-15713-libsoup-memory-leak-in-http-2-stream-termination"},{"cve":"CVE-2026-15711","cvss":7.5,"slug":"cve-2026-15711-gnome-libsoup-denial-of-service-via-oversized-websocket-control","title":"GNOME libsoup denial of service via oversized WebSocket control frame","severity":"high","exploited":false,"published_at":"2026-07-14T20:16:57.177+00:00","url":"https://junglewise.ai/threats/cve-2026-15711-gnome-libsoup-denial-of-service-via-oversized-websocket-control"},{"cve":"CVE-2026-15709","cvss":7.5,"slug":"cve-2026-15709-libsoup-websocket-unbounded-decompression-memory-exhaustion","title":"libsoup WebSocket unbounded decompression memory exhaustion","severity":"high","exploited":false,"published_at":"2026-07-14T20:16:57.027+00:00","url":"https://junglewise.ai/threats/cve-2026-15709-libsoup-websocket-unbounded-decompression-memory-exhaustion"},{"cve":"CVE-2026-15712","cvss":5.9,"slug":"cve-2026-15712-gnome-libsoup-heap-buffer-over-read-in-http-2-goaway-frame","title":"GNOME libsoup heap buffer over-read in HTTP/2 GOAWAY frame parsing","severity":"medium","exploited":false,"published_at":"2026-07-14T19:16:51.313+00:00","url":"https://junglewise.ai/threats/cve-2026-15712-gnome-libsoup-heap-buffer-over-read-in-http-2-goaway-frame"},{"cve":"CVE-2026-12478","cvss":4.8,"slug":"cve-2026-12478-gnome-libsoup-out-of-bounds-read-in-websocket-frame-processing","title":"GNOME libsoup out-of-bounds read in WebSocket frame processing","severity":"medium","exploited":false,"published_at":"2026-07-14T10:16:30.957+00:00","url":"https://junglewise.ai/threats/cve-2026-12478-gnome-libsoup-out-of-bounds-read-in-websocket-frame-processing"},{"cve":"CVE-2026-12549","cvss":4.8,"slug":"cve-2026-12549-gnome-libsoup-buffer-access-error-in-range-header-parsing","title":"GNOME libsoup buffer access error in Range header parsing","severity":"medium","exploited":false,"published_at":"2026-06-22T16:16:34.09+00:00","url":"https://junglewise.ai/threats/cve-2026-12549-gnome-libsoup-buffer-access-error-in-range-header-parsing"},{"cve":"CVE-2026-6324","cvss":4.8,"slug":"cve-2026-6324-gnome-libsoup-http-request-smuggling-in-soup-body-input-stream","title":"GNOME libsoup HTTP request smuggling in soup_body_input_stream_read_chunked","severity":"medium","exploited":false,"published_at":"2026-05-29T07:16:14.327+00:00","url":"https://junglewise.ai/threats/cve-2026-6324-gnome-libsoup-http-request-smuggling-in-soup-body-input-stream"},{"cve":"CVE-2026-5119","cvss":5.9,"epss":0.0001,"slug":"cve-2026-5119-gnome-libsoup-cleartext-cookie-disclosure-in-https-proxy-tunneling","title":"GNOME libsoup cleartext cookie disclosure in HTTPS proxy tunneling","severity":"medium","exploited":false,"published_at":"2026-03-30T07:15:58.35+00:00","url":"https://junglewise.ai/threats/cve-2026-5119-gnome-libsoup-cleartext-cookie-disclosure-in-https-proxy-tunneling"},{"cve":"CVE-2026-4271","cvss":5.3,"epss":0.0088,"slug":"cve-2026-4271-gnome-libsoup-use-after-free-in-http-2-server-implementation","title":"GNOME libsoup use-after-free in HTTP/2 server implementation","severity":"medium","exploited":false,"published_at":"2026-03-17T12:16:13.28+00:00","url":"https://junglewise.ai/threats/cve-2026-4271-gnome-libsoup-use-after-free-in-http-2-server-implementation"},{"cve":"CVE-2026-1761","cvss":8.6,"epss":0.0095,"slug":"cve-2026-1761-gnome-libsoup-stack-based-buffer-overflow-in-multipart-response","title":"GNOME libsoup stack-based buffer overflow in multipart response parsing","severity":"high","exploited":false,"published_at":"2026-02-02T14:16:34.65+00:00","url":"https://junglewise.ai/threats/cve-2026-1761-gnome-libsoup-stack-based-buffer-overflow-in-multipart-response"},{"cve":"CVE-2026-0716","cvss":4.8,"epss":0.0039,"slug":"cve-2026-0716-libsoup-websocket-out-of-bounds-read-in-frame-processing","title":"libsoup WebSocket out-of-bounds read in frame processing","severity":"medium","exploited":false,"published_at":"2026-01-13T23:16:04.163+00:00","url":"https://junglewise.ai/threats/cve-2026-0716-libsoup-websocket-out-of-bounds-read-in-frame-processing"},{"cve":"CVE-2026-0719","cvss":8.6,"epss":0.0056,"slug":"cve-2026-0719-gnome-libsoup-stack-buffer-overflow-in-ntlm-authentication","title":"GNOME libsoup stack buffer overflow in NTLM authentication","severity":"high","exploited":false,"published_at":"2026-01-08T13:15:43.283+00:00","url":"https://junglewise.ai/threats/cve-2026-0719-gnome-libsoup-stack-buffer-overflow-in-ntlm-authentication"},{"cve":"CVE-2025-14523","cvss":8.2,"epss":0.005,"slug":"cve-2025-14523-gnome-libsoup-http-request-smuggling-via-duplicate-host-headers","title":"GNOME libsoup HTTP request smuggling via duplicate Host headers","severity":"high","exploited":false,"published_at":"2025-12-11T13:15:58.983+00:00","url":"https://junglewise.ai/threats/cve-2025-14523-gnome-libsoup-http-request-smuggling-via-duplicate-host-headers"},{"cve":"CVE-2025-12105","cvss":7.5,"epss":0.0042,"slug":"cve-2025-12105-gnome-libsoup-use-after-free-in-message-queue-handling","title":"GNOME libsoup use-after-free in message queue handling","severity":"high","exploited":false,"published_at":"2025-10-23T10:15:32.043+00:00","url":"https://junglewise.ai/threats/cve-2025-12105-gnome-libsoup-use-after-free-in-message-queue-handling"},{"cve":"CVE-2025-11021","cvss":7.5,"epss":0.0059,"slug":"cve-2025-11021-gnome-libsoup-out-of-bounds-read-in-cookie-date-handling","title":"GNOME libsoup out-of-bounds read in cookie date handling","severity":"high","exploited":false,"published_at":"2025-09-26T09:15:31.37+00:00","url":"https://junglewise.ai/threats/cve-2025-11021-gnome-libsoup-out-of-bounds-read-in-cookie-date-handling"},{"cve":"CVE-2025-9901","cvss":5.9,"epss":0.0043,"slug":"cve-2025-9901-gnome-libsoup-information-disclosure-in-soupcache-via-http-vary","title":"GNOME libsoup information disclosure in SoupCache via HTTP Vary header","severity":"medium","exploited":false,"published_at":"2025-09-03T13:15:50.133+00:00","url":"https://junglewise.ai/threats/cve-2025-9901-gnome-libsoup-information-disclosure-in-soupcache-via-http-vary"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Gnome GLib","slug":"glib","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/glib"},{"name":"Gnome Libxslt","slug":"libxslt","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/libxslt"},{"name":"Gnome Gdk-Pixbuf","slug":"gdk-pixbuf","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/gdk-pixbuf"},{"name":"Gnome Gvfs","slug":"gvfs","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/gvfs"},{"name":"Gnome Localsearch","slug":"localsearch","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/localsearch"},{"name":"Gnome Glib-Networking","slug":"glib-networking","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/glib-networking"}],"technology":{"hub":true,"name":"Gnome Libsoup","slug":"libsoup","vendor":{"name":"Gnome","slug":"gnome","url":"https://junglewise.ai/threats/vendors/gnome"},"aliases":[],"category":"library","homepage":"https://wiki.gnome.org/Projects/libsoup","repo_url":"https://gitlab.gnome.org/GNOME/libsoup","description":"An HTTP client/server library for GNOME that uses GObjects and the glib main loop.","url":"https://junglewise.ai/threats/technologies/libsoup"},"most_severe":[{"cve":"CVE-2026-1761","cvss":8.6,"epss":0.0095,"slug":"cve-2026-1761-gnome-libsoup-stack-based-buffer-overflow-in-multipart-response","title":"GNOME libsoup stack-based buffer overflow in multipart response parsing","severity":"high","exploited":false,"published_at":"2026-02-02T14:16:34.65+00:00","url":"https://junglewise.ai/threats/cve-2026-1761-gnome-libsoup-stack-based-buffer-overflow-in-multipart-response"},{"cve":"CVE-2026-0719","cvss":8.6,"epss":0.0056,"slug":"cve-2026-0719-gnome-libsoup-stack-buffer-overflow-in-ntlm-authentication","title":"GNOME libsoup stack buffer overflow in NTLM authentication","severity":"high","exploited":false,"published_at":"2026-01-08T13:15:43.283+00:00","url":"https://junglewise.ai/threats/cve-2026-0719-gnome-libsoup-stack-buffer-overflow-in-ntlm-authentication"},{"cve":"CVE-2025-14523","cvss":8.2,"epss":0.005,"slug":"cve-2025-14523-gnome-libsoup-http-request-smuggling-via-duplicate-host-headers","title":"GNOME libsoup HTTP request smuggling via duplicate Host headers","severity":"high","exploited":false,"published_at":"2025-12-11T13:15:58.983+00:00","url":"https://junglewise.ai/threats/cve-2025-14523-gnome-libsoup-http-request-smuggling-via-duplicate-host-headers"},{"cve":"CVE-2026-85197","cvss":7.6,"epss":0.0041,"slug":"cve-2026-85197-gnome-libsoup-heap-use-after-free-in-http-2-client","title":"GNOME libsoup heap use-after-free in HTTP/2 client","severity":"high","exploited":false,"published_at":"2026-09-04T08:17:16.677+00:00","url":"https://junglewise.ai/threats/cve-2026-85197-gnome-libsoup-heap-use-after-free-in-http-2-client"},{"cve":"CVE-2025-11021","cvss":7.5,"epss":0.0059,"slug":"cve-2025-11021-gnome-libsoup-out-of-bounds-read-in-cookie-date-handling","title":"GNOME libsoup out-of-bounds read in cookie date handling","severity":"high","exploited":false,"published_at":"2025-09-26T09:15:31.37+00:00","url":"https://junglewise.ai/threats/cve-2025-11021-gnome-libsoup-out-of-bounds-read-in-cookie-date-handling"},{"cve":"CVE-2025-12105","cvss":7.5,"epss":0.0042,"slug":"cve-2025-12105-gnome-libsoup-use-after-free-in-message-queue-handling","title":"GNOME libsoup use-after-free in message queue handling","severity":"high","exploited":false,"published_at":"2025-10-23T10:15:32.043+00:00","url":"https://junglewise.ai/threats/cve-2025-12105-gnome-libsoup-use-after-free-in-message-queue-handling"},{"cve":"CVE-2026-15711","cvss":7.5,"slug":"cve-2026-15711-gnome-libsoup-denial-of-service-via-oversized-websocket-control","title":"GNOME libsoup denial of service via oversized WebSocket control frame","severity":"high","exploited":false,"published_at":"2026-07-14T20:16:57.177+00:00","url":"https://junglewise.ai/threats/cve-2026-15711-gnome-libsoup-denial-of-service-via-oversized-websocket-control"},{"cve":"CVE-2026-15709","cvss":7.5,"slug":"cve-2026-15709-libsoup-websocket-unbounded-decompression-memory-exhaustion","title":"libsoup WebSocket unbounded decompression memory exhaustion","severity":"high","exploited":false,"published_at":"2026-07-14T20:16:57.027+00:00","url":"https://junglewise.ai/threats/cve-2026-15709-libsoup-websocket-unbounded-decompression-memory-exhaustion"},{"cve":"CVE-2026-66337","cvss":6.5,"slug":"cve-2026-66337-gnome-libsoup-heap-buffer-over-read-in-soup-filter-input-stream","title":"GNOME libsoup heap buffer over-read in soup_filter_input_stream_read_until","severity":"medium","exploited":false,"published_at":"2026-07-24T23:16:51.76+00:00","url":"https://junglewise.ai/threats/cve-2026-66337-gnome-libsoup-heap-buffer-over-read-in-soup-filter-input-stream"},{"cve":"CVE-2026-15714","cvss":6.5,"slug":"cve-2026-15714-gnome-libsoup-out-of-bounds-read-in-multipart-boundary-processing","title":"GNOME libsoup out-of-bounds read in multipart boundary processing","severity":"medium","exploited":false,"published_at":"2026-07-14T20:16:57.56+00:00","url":"https://junglewise.ai/threats/cve-2026-15714-gnome-libsoup-out-of-bounds-read-in-multipart-boundary-processing"}],"generated_at":"2026-09-26T09:24:00.138874+00:00"}