Description

A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Carriage Return Line Feed) injection, occurs because the method value is not properly escaped during request line construction, potentially leading to HTTP request injection.

INFO

Published Date :

2026-03-17T09:44:19.794Z

Last Modified :

2026-03-19T20:57:05.472Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-3633 vulnerability.

Vendors Products
Gnome
  • Libsoup
Libsoup
  • Libsoup
Redhat
  • Enterprise Linux

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact