It was discovered that libsoup did not correctly handle certain URL-decoded input, which could allow for HTTP header injection. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-1467, CVE-2026-1536) It was discovered that libsoup did not correctly handle removal of the Proxy-Authorization header. A remote attacker could possibly use this issue to leak sensitive information. (CVE-2026-1539)
Continue reading...
Continue reading...

