CVE-2026-2369 identifies an integer underflow vulnerability within the libsoup library, triggered when processing content with a zero-length resource, which results in a buffer overread. This flaw carries a Medium CVSS score of 6.5 and can be exploited remotely with low attack complexity and no user interaction. A successful exploit could lead to low impact on confidentiality by allowing access to sensitive information, or cause an application-level denial of service. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. However, the vulnerability has received some community discussion and media coverage, primarily through security advisories from vendors like SUSE, indicating that patches are being issued.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:gnome:libsoup:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
libsoup vulnerabilities
Jul 9, 2026Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources
Mar 10, 2026libsoup: libsoup: Buffer overread due to integer underflow when handling zero-length resources
Feb 11, 2026