CVE-2026-1761
HIGHDescription
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to memory corruption. This issue may result in application crashes or arbitrary code execution in applications that process untrusted server responses, and it does not require authentication or user interaction.
CVSS v3 Vector
Exploitability
Impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Exploit Intelligence
Moderate risk: more likely to be exploited than 57% of all known CVEs.
References
- https://access.redhat.com/errata/RHSA-2026:1948
- https://access.redhat.com/errata/RHSA-2026:2005
- https://access.redhat.com/errata/RHSA-2026:2006
- https://access.redhat.com/errata/RHSA-2026:2007
- https://access.redhat.com/errata/RHSA-2026:2008
- https://access.redhat.com/errata/RHSA-2026:2049
- https://access.redhat.com/errata/RHSA-2026:2182
- https://access.redhat.com/errata/RHSA-2026:2214
- https://access.redhat.com/errata/RHSA-2026:2215
- https://access.redhat.com/errata/RHSA-2026:2216
- https://access.redhat.com/errata/RHSA-2026:2396
- https://access.redhat.com/errata/RHSA-2026:2402
- https://access.redhat.com/errata/RHSA-2026:2410
- https://access.redhat.com/errata/RHSA-2026:2512
- https://access.redhat.com/errata/RHSA-2026:2513
- https://access.redhat.com/errata/RHSA-2026:2514
- https://access.redhat.com/errata/RHSA-2026:2528
- https://access.redhat.com/errata/RHSA-2026:2529
- https://access.redhat.com/errata/RHSA-2026:2628
- https://access.redhat.com/errata/RHSA-2026:2844
- https://access.redhat.com/security/cve/CVE-2026-1761
- https://bugzilla.redhat.com/show_bug.cgi?id=2435961
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/493
Find and fix vulnerabilities across your fleet
TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
Start freeThis product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-03-19.