Medium severity6.5NVD Advisory· Published Jul 24, 2026· Updated Aug 24, 2026
CVE-2026-66337
CVE-2026-66337
Description
A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingVendor Advisory
- access.redhat.com/security/cve/CVE-2026-66337nvdVendor Advisory
News mentions
0No linked articles in our index yet.