Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-76736.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-76736
Upstream
  • CVE-2026-1801
Published
2026-02-03T21:16:12Z
Modified
2026-04-21T04:39:06.051375Z
Summary
CVE-2026-1801 affecting package libsoup 3.0.4-12
Details

A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soupfilterinputstreamread_line() logic, where libsoup accepts malformed chunk headers, such as lone line feed (LF) characters instead of the required carriage return and line feed (CRLF). A remote attacker can exploit this without authentication or user interaction by sending specially crafted chunked requests. This allows libsoup to parse and process multiple HTTP requests from a single network message, potentially leading to information disclosure.

References

Affected packages

Azure Linux:2 / libsoup

Package

Name
libsoup
Purl
pkg:rpm/azure-linux/libsoup

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.0.4-12

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-76736.json"