Bug 2433180 - CVE-2026-1467 libsoup3: libsoup: HTTP header injection via specially crafted URLs when an HTTP proxy is configured [fedora-43]
Summary: CVE-2026-1467 libsoup3: libsoup: HTTP header injection via specially crafted ...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: libsoup3
Version: 43
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Gwyn Ciesla
QA Contact:
URL:
Whiteboard: {"flaws": ["5b09fa6c-1e88-4ef2-b30e-1...
Depends On:
Blocks: CVE-2026-1467
TreeView+ depends on / blocked
 
Reported: 2026-01-27 08:21 UTC by Abhishek Raj
Modified: 2026-03-19 14:03 UTC (History)
3 users (show)

Fixed In Version: libsoup3-3.6.6-1.fc43
Clone Of:
Environment:
Last Closed: 2026-03-19 14:03:34 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
GNOME Gitlab GNOME libsoup issues 488 0 None closed (CVE-2026-1467) libsoup: CRLF injection in URL when a proxy is in use 2026-03-19 14:03:34 UTC

Description Abhishek Raj 2026-01-27 08:21:56 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Milan Crha 2026-03-19 14:03:34 UTC
Fixed in 3.6.6 by https://gitlab.gnome.org/GNOME/libsoup/-/commit/6dfe506618d2d5856618e5c0f85bd93386dc8012 as a cherry-pick of a merge request for the https://gitlab.gnome.org/GNOME/libsoup/-/issues/488


Note You need to log in before you can comment on or make changes to this bug.