CVE-2025-2784EPSS p52.6%
CVE-2025-2784CVE-2025-2784
gnome / libsoup
Description
A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.
Scoring
| CVSS | 7.0 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H |
| EPSS | 0.78% probability of exploitation · percentile 52.6% · 2026-08-11T12:00:17Z |
| Last modified | 2026-06-30 |