Fedora Account System
Red Hat Associate
Red Hat Customer
An unsigned integer underflow in soup_filter_input_stream_read_until() in libsoup/soup-filter-input-stream.c causes a heap buffer over-read when parsing multipart HTTP responses. When include_boundary is FALSE and the internal buffer contains fewer bytes than the boundary string length, the subtraction of two unsigned values wraps to a very large number, causing the boundary scan loop to read beyond the heap allocation. A malicious HTTP server can trigger this against any libsoup client using SoupMultipartInputStream. This is related to but distinct from CVE-2026-1761 — Red Hat's downstream fix for that CVE does not resolve this issue. Upstream report: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/532 PSIRTSUPT: https://redhat.atlassian.net/browse/PSIRTSUPT-17666