Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-80226.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-80226
Upstream
  • CVE-2026-3634
Published
2026-03-17T10:16:00Z
Modified
2026-08-28T17:47:53.232555558Z
Summary
CVE-2026-3634 affecting package libsoup 3.4.4-16
Details

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the soup_message_headers_set_content_type() function. This vulnerability allows for the injection of arbitrary header-value pairs, potentially leading to HTTP header injection and response splitting attacks.

References

Affected packages

Azure Linux:3 / libsoup

Package

Name
libsoup
Purl
pkg:rpm/azure-linux/libsoup

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.4.4-16

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-80226.json"