Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94101.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94101
Upstream
  • CVE-2026-66337
Published
2026-07-24T23:16:51Z
Modified
2026-08-31T05:26:27Z
Summary
CVE-2026-66337 affecting package libsoup 3.4.4-16
Details

A flaw was found in libsoup. An unsigned integer underflow in the soupfilterinputstreamread_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory.

References

Affected packages

Azure Linux:3 / libsoup

Package

Name
libsoup
Purl
pkg:rpm/azure-linux/libsoup

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.4.4-16

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94101.json"