9
CVE-2025-32911 - Libsoup: double free on soup_message_headers_get_content_disposition() through "soup-message-headβ¦
A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.
7.5
CVE-2025-32913 - Libsoup: null pointer dereference in soup_message_headers_get_content_disposition when "filename" β¦
A flaw was found in libsoup, where the soup_message_headers_get_content_disposition() function is vulnerable to a NULL pointer dereference. This flaw allows a malicious HTTP peer to crash a libsoup client or server that uses this function.
7.5
CVE-2025-32908 - Libsoup: denial of service on libsoup through http/2 server
A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of pseudo-headers :scheme, :authority, and :path, which may allow a user to cause a denial of service (DoS).
7.5
CVE-2025-32906 - Libsoup: out of bounds reads in soup_headers_parse_request()
A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.
6.5
CVE-2025-32912 - Libsoup: null pointer dereference in client when server omits the "nonce" parameter in an unauthorβ¦
A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.
5.3
CVE-2025-32907 - Libsoup: denial of service in server when client requests a large amount of overlapping ranges witβ¦
A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a fullβ¦
4.8
CVE-2025-29720 -
Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.
7.4
CVE-2025-32914 - Libsoup: oob read on libsoup through function "soup_multipart_new_from_message" in soup-multipart.β¦
A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds.
0.0
CVE-2025-32930 -
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA.
5.3
CVE-2025-32909 - Libsoup: null pointer dereference on libsoup through function "sniff_mp4" in soup-content-sniffer.c
A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash.