Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gnome
Gnome libsoup |
|
| Vendors & Products |
Gnome
Gnome libsoup |
Fri, 29 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Fri, 29 May 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` function by sending a malicious HTTP request. This vulnerability occurs when libsoup operates behind a non-libsoup proxy server or as a proxy in front of a non-libsoup backend server. Successful exploitation can allow an attacker to bypass security controls, poison web caches, or gain unauthorized access. | |
| Title | Libsoup: libsoup: http request smuggling via unsigned to signed conversion error | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-444 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-05-29T14:01:04.526Z
Reserved: 2026-04-14T20:50:53.403Z
Link: CVE-2026-6324
Updated: 2026-05-29T14:00:59.497Z
Status : Awaiting Analysis
Published: 2026-05-29T07:16:14.327
Modified: 2026-05-29T15:16:25.023
Link: CVE-2026-6324
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:19:03Z