The libsoup packages provide an HTTP client and server library for GNOME.
Security Fix(es):
- libsoup: Heap buffer over-read in
skip_insignificant_space
when sniffing content (CVE-2025-2784)
- libsoup: Denial of Service attack to websocket server (CVE-2025-32049)
- libsoup: OOB Read on libsoup through function "soupmultipartnewfrommessage" in soup-multipart.c leads to crash or exit of process (CVE-2025-32914)
- libsoup: Integer Underflow in soupmultipartnewfrommessage() Leading to Denial of Service in libsoup (CVE-2025-4948)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.