libsoup's HTTP/2 server doesn't fully validate the values of the pseudo-headers :scheme, :authority, and :path. A client may crash the server by sending a malicious HTTP request.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:7505 https://access.redhat.com/errata/RHSA-2025:7505