OESA-2026-1449

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-1449
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-1449.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-1449
Upstream
  • CVE-2026-1760
  • CVE-2026-1801
  • CVE-2026-2369
Published
2026-02-28T12:44:33Z
Modified
2026-02-28T13:03:13.980370Z
Summary
libsoup security update
Details

libsoup is an HTTP client/server library for GNOME. It uses GObjects and the glib main loop, to integrate well with GNOME applications, and also has a synchronous API, for use in threaded applications.

Security Fix(es):

A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles requests that combine Transfer-Encoding: chunked and Connection: keep-alive headers. A remote, unauthenticated client can exploit this by sending specially crafted requests, causing SoupServer to fail to close the connection as required by RFC 9112. This allows the attacker to smuggle additional requests over the persistent connection, leading to unintended request processing and potential denial-of-service (DoS) conditions.(CVE-2026-1760)

A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soupfilterinputstreamread_line() logic, where libsoup accepts malformed chunk headers, such as lone line feed (LF) characters instead of the required carriage return and line feed (CRLF). A remote attacker can exploit this without authentication or user interaction by sending specially crafted chunked requests. This allows libsoup to parse and process multiple HTTP requests from a single network message, potentially leading to information disclosure.(CVE-2026-1801)

libsoup: libsoup: Buffer overread due to integer underflow when handling zero-length resources(CVE-2026-2369)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:20.03-LTS-SP4
libsoup

Package

Name
libsoup
Purl
pkg:rpm/openEuler/libsoup&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.71.0-12.oe2003sp4

Ecosystem specific

{
    "src": [
        "libsoup-2.71.0-12.oe2003sp4.src.rpm"
    ],
    "aarch64": [
        "libsoup-2.71.0-12.oe2003sp4.aarch64.rpm",
        "libsoup-debuginfo-2.71.0-12.oe2003sp4.aarch64.rpm",
        "libsoup-debugsource-2.71.0-12.oe2003sp4.aarch64.rpm",
        "libsoup-devel-2.71.0-12.oe2003sp4.aarch64.rpm"
    ],
    "x86_64": [
        "libsoup-2.71.0-12.oe2003sp4.x86_64.rpm",
        "libsoup-debuginfo-2.71.0-12.oe2003sp4.x86_64.rpm",
        "libsoup-debugsource-2.71.0-12.oe2003sp4.x86_64.rpm",
        "libsoup-devel-2.71.0-12.oe2003sp4.x86_64.rpm"
    ],
    "noarch": [
        "libsoup-help-2.71.0-12.oe2003sp4.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1449.json"
openEuler:22.03-LTS-SP4
libsoup

Package

Name
libsoup
Purl
pkg:rpm/openEuler/libsoup&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.74.2-13.oe2203sp4

Ecosystem specific

{
    "src": [
        "libsoup-2.74.2-13.oe2203sp4.src.rpm"
    ],
    "aarch64": [
        "libsoup-2.74.2-13.oe2203sp4.aarch64.rpm",
        "libsoup-debuginfo-2.74.2-13.oe2203sp4.aarch64.rpm",
        "libsoup-debugsource-2.74.2-13.oe2203sp4.aarch64.rpm",
        "libsoup-devel-2.74.2-13.oe2203sp4.aarch64.rpm"
    ],
    "x86_64": [
        "libsoup-2.74.2-13.oe2203sp4.x86_64.rpm",
        "libsoup-debuginfo-2.74.2-13.oe2203sp4.x86_64.rpm",
        "libsoup-debugsource-2.74.2-13.oe2203sp4.x86_64.rpm",
        "libsoup-devel-2.74.2-13.oe2203sp4.x86_64.rpm"
    ],
    "noarch": [
        "libsoup-help-2.74.2-13.oe2203sp4.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1449.json"
openEuler:24.03-LTS
libsoup

Package

Name
libsoup
Purl
pkg:rpm/openEuler/libsoup&distro=openEuler-24.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.74.3-14.oe2403sp3

Ecosystem specific

{
    "src": [
        "libsoup-2.74.3-13.oe2403.src.rpm",
        "libsoup-2.74.3-13.oe2403sp1.src.rpm",
        "libsoup-2.74.3-13.oe2403sp2.src.rpm",
        "libsoup-2.74.3-14.oe2403sp3.src.rpm"
    ],
    "aarch64": [
        "libsoup-2.74.3-13.oe2403.aarch64.rpm",
        "libsoup-debuginfo-2.74.3-13.oe2403.aarch64.rpm",
        "libsoup-debugsource-2.74.3-13.oe2403.aarch64.rpm",
        "libsoup-devel-2.74.3-13.oe2403.aarch64.rpm",
        "libsoup-2.74.3-13.oe2403sp1.aarch64.rpm",
        "libsoup-debuginfo-2.74.3-13.oe2403sp1.aarch64.rpm",
        "libsoup-debugsource-2.74.3-13.oe2403sp1.aarch64.rpm",
        "libsoup-devel-2.74.3-13.oe2403sp1.aarch64.rpm",
        "libsoup-2.74.3-13.oe2403sp2.aarch64.rpm",
        "libsoup-debuginfo-2.74.3-13.oe2403sp2.aarch64.rpm",
        "libsoup-debugsource-2.74.3-13.oe2403sp2.aarch64.rpm",
        "libsoup-devel-2.74.3-13.oe2403sp2.aarch64.rpm",
        "libsoup-2.74.3-14.oe2403sp3.aarch64.rpm",
        "libsoup-debuginfo-2.74.3-14.oe2403sp3.aarch64.rpm",
        "libsoup-debugsource-2.74.3-14.oe2403sp3.aarch64.rpm",
        "libsoup-devel-2.74.3-14.oe2403sp3.aarch64.rpm"
    ],
    "x86_64": [
        "libsoup-2.74.3-13.oe2403.x86_64.rpm",
        "libsoup-debuginfo-2.74.3-13.oe2403.x86_64.rpm",
        "libsoup-debugsource-2.74.3-13.oe2403.x86_64.rpm",
        "libsoup-devel-2.74.3-13.oe2403.x86_64.rpm",
        "libsoup-2.74.3-13.oe2403sp1.x86_64.rpm",
        "libsoup-debuginfo-2.74.3-13.oe2403sp1.x86_64.rpm",
        "libsoup-debugsource-2.74.3-13.oe2403sp1.x86_64.rpm",
        "libsoup-devel-2.74.3-13.oe2403sp1.x86_64.rpm",
        "libsoup-2.74.3-13.oe2403sp2.x86_64.rpm",
        "libsoup-debuginfo-2.74.3-13.oe2403sp2.x86_64.rpm",
        "libsoup-debugsource-2.74.3-13.oe2403sp2.x86_64.rpm",
        "libsoup-devel-2.74.3-13.oe2403sp2.x86_64.rpm",
        "libsoup-2.74.3-14.oe2403sp3.x86_64.rpm",
        "libsoup-debuginfo-2.74.3-14.oe2403sp3.x86_64.rpm",
        "libsoup-debugsource-2.74.3-14.oe2403sp3.x86_64.rpm",
        "libsoup-devel-2.74.3-14.oe2403sp3.x86_64.rpm"
    ],
    "noarch": [
        "libsoup-help-2.74.3-13.oe2403.noarch.rpm",
        "libsoup-help-2.74.3-13.oe2403sp1.noarch.rpm",
        "libsoup-help-2.74.3-13.oe2403sp2.noarch.rpm",
        "libsoup-help-2.74.3-14.oe2403sp3.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1449.json"
openEuler:24.03-LTS-SP1
libsoup

Package

Name
libsoup
Purl
pkg:rpm/openEuler/libsoup&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.74.3-13.oe2403sp1

Ecosystem specific

{
    "src": [
        "libsoup-2.74.3-13.oe2403sp1.src.rpm"
    ],
    "aarch64": [
        "libsoup-2.74.3-13.oe2403sp1.aarch64.rpm",
        "libsoup-debuginfo-2.74.3-13.oe2403sp1.aarch64.rpm",
        "libsoup-debugsource-2.74.3-13.oe2403sp1.aarch64.rpm",
        "libsoup-devel-2.74.3-13.oe2403sp1.aarch64.rpm"
    ],
    "x86_64": [
        "libsoup-2.74.3-13.oe2403sp1.x86_64.rpm",
        "libsoup-debuginfo-2.74.3-13.oe2403sp1.x86_64.rpm",
        "libsoup-debugsource-2.74.3-13.oe2403sp1.x86_64.rpm",
        "libsoup-devel-2.74.3-13.oe2403sp1.x86_64.rpm"
    ],
    "noarch": [
        "libsoup-help-2.74.3-13.oe2403sp1.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1449.json"
openEuler:24.03-LTS-SP2
libsoup

Package

Name
libsoup
Purl
pkg:rpm/openEuler/libsoup&distro=openEuler-24.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.74.3-13.oe2403sp2

Ecosystem specific

{
    "src": [
        "libsoup-2.74.3-13.oe2403sp2.src.rpm"
    ],
    "aarch64": [
        "libsoup-2.74.3-13.oe2403sp2.aarch64.rpm",
        "libsoup-debuginfo-2.74.3-13.oe2403sp2.aarch64.rpm",
        "libsoup-debugsource-2.74.3-13.oe2403sp2.aarch64.rpm",
        "libsoup-devel-2.74.3-13.oe2403sp2.aarch64.rpm"
    ],
    "x86_64": [
        "libsoup-2.74.3-13.oe2403sp2.x86_64.rpm",
        "libsoup-debuginfo-2.74.3-13.oe2403sp2.x86_64.rpm",
        "libsoup-debugsource-2.74.3-13.oe2403sp2.x86_64.rpm",
        "libsoup-devel-2.74.3-13.oe2403sp2.x86_64.rpm"
    ],
    "noarch": [
        "libsoup-help-2.74.3-13.oe2403sp2.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1449.json"
openEuler:24.03-LTS-SP3
libsoup

Package

Name
libsoup
Purl
pkg:rpm/openEuler/libsoup&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.74.3-14.oe2403sp3

Ecosystem specific

{
    "src": [
        "libsoup-2.74.3-14.oe2403sp3.src.rpm"
    ],
    "aarch64": [
        "libsoup-2.74.3-14.oe2403sp3.aarch64.rpm",
        "libsoup-debuginfo-2.74.3-14.oe2403sp3.aarch64.rpm",
        "libsoup-debugsource-2.74.3-14.oe2403sp3.aarch64.rpm",
        "libsoup-devel-2.74.3-14.oe2403sp3.aarch64.rpm"
    ],
    "x86_64": [
        "libsoup-2.74.3-14.oe2403sp3.x86_64.rpm",
        "libsoup-debuginfo-2.74.3-14.oe2403sp3.x86_64.rpm",
        "libsoup-debugsource-2.74.3-14.oe2403sp3.x86_64.rpm",
        "libsoup-devel-2.74.3-14.oe2403sp3.x86_64.rpm"
    ],
    "noarch": [
        "libsoup-help-2.74.3-14.oe2403sp3.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1449.json"