GHSA-7hqq-7crg-xr49HighCVSS 7.5
A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of...
🔗 CVE IDs covered (1)
📋 Description
A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of pseudo-headers :scheme, :authority, and :path, which may allow a user to cause a denial of service (DoS).
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2025-32908
- https://access.redhat.com/security/cve/CVE-2025-32908
- https://bugzilla.redhat.com/show_bug.cgi?id=2359343
- https://access.redhat.com/errata/RHSA-2025:7505
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/429
- https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/451
- https://github.com/advisories/GHSA-7hqq-7crg-xr49