CVE-2025-32907 describes a resource consumption vulnerability in libsoup's HTTP range request implementation, allowing a malicious client to exhaust server memory through repeated range requests in a single HTTP call. This flaw has a CVSS score of 5.3 (MEDIUM), indicating a low-impact availability issue that does not lead to a full denial of service. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 9 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025libsoup: Denial of service in server when client requests a large amount of overlapping ranges with Range header
Apr 14, 2025Libsoup: denial of service in server when client requests a large amount of overlapping ranges with range header
Apr 8, 2025