Low severity3.9NVD Advisory· Published Mar 17, 2026· Updated Jun 17, 2026
CVE-2026-3633
CVE-2026-3633
Description
A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the soup_message_new() function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Carriage Return Line Feed) injection, occurs because the method value is not properly escaped during request line construction, potentially leading to HTTP request injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:/o:redhat:enterprise_linux:10+ 9 more
- cpe:/o:redhat:enterprise_linux:10
- cpe:/o:redhat:enterprise_linux:6
- cpe:/o:redhat:enterprise_linux:7
- cpe:/o:redhat:enterprise_linux:8
- cpe:/o:redhat:enterprise_linux:9
- cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:gnome:libsoup:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gnome:libsoup:-:*:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
3- gitlab.gnome.org/GNOME/libsoup/-/issues/484nvdExploitIssue TrackingVendor Advisory
- access.redhat.com/security/cve/CVE-2026-3633nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.