High severity8.6NVD Advisory· Published Jan 8, 2026· Updated Apr 15, 2026
CVE-2026-0719
CVE-2026-0719
Description
A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can overflow due to improper use of signed integers. This results in incorrect memory allocation on the stack, followed by unsafe memory copying. As a result, applications using libsoup may crash unexpectedly, creating a denial-of-service risk.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
22- access.redhat.com/errata/RHSA-2026:1948nvd
- access.redhat.com/errata/RHSA-2026:2005nvd
- access.redhat.com/errata/RHSA-2026:2006nvd
- access.redhat.com/errata/RHSA-2026:2007nvd
- access.redhat.com/errata/RHSA-2026:2008nvd
- access.redhat.com/errata/RHSA-2026:2049nvd
- access.redhat.com/errata/RHSA-2026:2182nvd
- access.redhat.com/errata/RHSA-2026:2214nvd
- access.redhat.com/errata/RHSA-2026:2215nvd
- access.redhat.com/errata/RHSA-2026:2216nvd
- access.redhat.com/errata/RHSA-2026:2396nvd
- access.redhat.com/errata/RHSA-2026:2402nvd
- access.redhat.com/errata/RHSA-2026:2512nvd
- access.redhat.com/errata/RHSA-2026:2513nvd
- access.redhat.com/errata/RHSA-2026:2514nvd
- access.redhat.com/errata/RHSA-2026:2528nvd
- access.redhat.com/errata/RHSA-2026:2529nvd
- access.redhat.com/errata/RHSA-2026:2628nvd
- access.redhat.com/errata/RHSA-2026:2844nvd
- access.redhat.com/security/cve/CVE-2026-0719nvd
- bugzilla.redhat.com/show_bug.cginvd
- gitlab.gnome.org/GNOME/libsoup/-/issues/477nvd
News mentions
0No linked articles in our index yet.