Bug 2543949 (CVE-2026-103399) - CVE-2026-103399 libsoup: SoupServer: HTTP/1 request smuggling via undrained Expect: 100-continue body
Summary: CVE-2026-103399 libsoup: SoupServer: HTTP/1 request smuggling via undrained E...
Keywords:
Status: NEW
Alias: CVE-2026-103399
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2543957 2543958 2543959
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-30 14:45 UTC by OSIDB Bzimport
Modified: 2026-09-30 17:15 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-30 14:45:41 UTC
HTTP/1 request-smuggling desync in SoupServer: when a client sends Expect: 100-continue with a Content-Length body and SoupServer emits an early final (non-1xx) response before reading the body (e.g. 401 from SoupAuthDomain, or any handler that sets a final status at the headers stage), libsoup marks the read side DONE without draining the declared body bytes and without sending Connection: close. On a keep-alive connection those leftover body bytes are then parsed as the next HTTP request, so a complete second request placed in the body is smuggled and executed (CWE-444 / RFC 9112 framing violation).

Verified upstream on libsoup 3.7.1 / current HEAD: one crafted connection to an auth-protected path yields 401 then 200, and the smuggled handler runs. Defect location: libsoup/server/http1/soup-server-message-io-http1.c io_write() STATE_HEADERS Expect: 100-continue path (read_state -> DONE without drain/close).

Distinct from CVE-2026-1760 (chunked + keep-alive close) and CVE-2026-1801 (malformed chunk headers). Upstream: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/539. Reporter: Jianqiang (Stark) Li. Embargo: No. Patch discussed upstream; fixed release not yet shipped.


Note You need to log in before you can comment on or make changes to this bug.