Ghostwire

CVE-2026-2708: A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The...

HIGH CVSS 7.5

Published: April 23, 2026 | Last Modified: April 23, 2026

Description

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (8 articles)

References