Bug 2543957 - CVE-2026-103399 mingw-libsoup: SoupServer: HTTP/1 request smuggling via undrained Expect: 100-continue body [fedora-all]
Summary: CVE-2026-103399 mingw-libsoup: SoupServer: HTTP/1 request smuggling via undra...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: mingw-libsoup
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Kalev Lember
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["c12b8efb-4982-4942-be00-b...
Depends On:
Blocks: CVE-2026-103399
TreeView+ depends on / blocked
 
Reported: 2026-09-30 14:49 UTC by Srikanth Balasubramanian
Modified: 2026-09-30 14:49 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Srikanth Balasubramanian 2026-09-30 14:49:08 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

HTTP/1 request-smuggling desync in SoupServer: when a client sends Expect: 100-continue with a Content-Length body and SoupServer emits an early final (non-1xx) response before reading the body (e.g. 401 from SoupAuthDomain, or any handler that sets a final status at the headers stage), libsoup marks the read side DONE without draining the declared body bytes and without sending Connection: close. On a keep-alive connection those leftover body bytes are then parsed as the next HTTP request, so a complete second request placed in the body is smuggled and executed (CWE-444 / RFC 9112 framing violation).

Verified upstream on libsoup 3.7.1 / current HEAD: one crafted connection to an auth-protected path yields 401 then 200, and the smuggled handler runs. Defect location: libsoup/server/http1/soup-server-message-io-http1.c io_write() STATE_HEADERS Expect: 100-continue path (read_state -> DONE without drain/close).

Distinct from CVE-2026-1760 (chunked + keep-alive close) and CVE-2026-1801 (malformed chunk headers). Upstream: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/539. Reporter: Jianqiang (Stark) Li. Embargo: No. Patch discussed upstream; fixed release not yet shipped.


Note You need to log in before you can comment on or make changes to this bug.