CVE-2026-1760 describes an HTTP request smuggling vulnerability in SoupServer, affecting products utilizing this library. This flaw arises from SoupServer's improper handling of requests combining Transfer-Encoding: chunked and Connection: keep-alive headers. A remote, unauthenticated attacker can exploit this with specially crafted requests, leading to persistent connections that fail to close as per RFC 9112. The vulnerability has a CVSS score of 5.3 (MEDIUM), indicating a network-based attack with low complexity, requiring no user interaction, and resulting in a low impact on availability (potential Denial of Service). While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community discussion and media coverage, primarily from SUSE security advisories.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 6 | Range not provided by sourceCNA affecteddefault unknown | |
| Red Hat | Red Hat Enterprise Linux 7 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 8 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 9 | All Versions ImpactedCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.