
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0719 is a stack-based buffer overflow vulnerability in the NTLM authentication handling of the libsoup HTTP client/server library, used by GNOME and numerous applications including WebKit, Evolution, GVfs, and gnome-online-accounts. The flaw exists in the md4sum() function within libsoup's NTLM authentication module (SoupAuthNTLM), where processing an extremely long password causes a signed-to-unsigned integer conversion error, leading to incorrect stack memory allocation and unsafe memory copying. It was disclosed on January 8, 2026, with patches released by Red Hat beginning February 4, 2026, and by Oracle on January 20, 2026. Affected products include libsoup across RHEL 7 through 10, Oracle Solaris 11.4, IBM Instana Observability (OnPrem), and IBM Netezza Appliance. The CVSS v3.1 base score is 8.6 (High), assigned by Red Hat (Red Hat CVE, Oracle Advisory).
The root cause is classified as CWE-121 (Stack-based Buffer Overflow), arising from a signed-to-unsigned integer conversion error in the md4sum() function of libsoup's NTLM authentication module. When a client or server processes an extremely long NTLM password, an internal size calculation overflows because signed integers are used where unsigned values are required, resulting in an undersized stack buffer allocation followed by an unsafe memcpy-style operation that overwrites adjacent stack memory. The attack vector is network-based (AV:N), requires no authentication (PR:N), and no user interaction (UI:N), making it exploitable by any remote party that can initiate an NTLM authentication exchange with a vulnerable application. Multiple widely deployed components enable NTLM by default, significantly broadening the attack surface (Red Hat Bugzilla, GNOME GitLab).
Successful exploitation can cause applications using libsoup to crash unexpectedly, resulting in a denial-of-service condition. Beyond availability, the stack-based buffer overflow may allow an attacker to overwrite adjacent stack memory, potentially enabling arbitrary code execution with the privileges of the affected application — which could include desktop applications, web clients, or system services running as elevated users. Given that components such as WebKit, Evolution, GVfs, and gnome-online-accounts enable NTLM by default, the scope of affected assets is broad, and exploitation could facilitate lateral movement or data exfiltration depending on the privileges of the compromised process (Red Hat Bugzilla, Feedly).
As of the time of this report, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Feedly). No threat actor attribution has been reported. The EPSS score is approximately 0.084%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the network-accessible, unauthenticated attack vector and the wide deployment of libsoup-dependent applications increase the potential risk if a reliable exploit is developed.
SoupAuthNTLM module.md4sum()).Authorization: NTLM header values (password fields significantly exceeding typical length limits).core.*) generated in application working directories following crashes of libsoup-dependent processes.The primary remediation is to update libsoup to a patched version. Red Hat has released fixes across multiple RHEL versions via advisories including RHSA-2026:1948 (RHEL 8.8), RHSA-2026:2005 (RHEL 9.2), RHSA-2026:2006 (RHEL 10.0 EUS), RHSA-2026:2007 (RHEL 9.4 EUS), RHSA-2026:2008 (RHEL 9.0), RHSA-2026:2049 (RHEL 9.6 EUS), RHSA-2026:2182 (RHEL 10), RHSA-2026:2214/2215 (RHEL 8), RHSA-2026:2216 (RHEL 9), and additional extended support releases through RHSA-2026:2844 (Red Hat Errata). Oracle Solaris 11.4 patches were included in the January 2026 Third Party Bulletin (Oracle Advisory). IBM has released fixes for Instana Observability (OnPrem) and Netezza Appliance. As a workaround where immediate patching is not possible, consider disabling NTLM authentication in libsoup-based applications or blocking NTLM negotiation at the network perimeter.
The vulnerability received coverage from security community aggregators including RedPacketSecurity and TheHackerWire on Mastodon/Infosec.exchange shortly after disclosure in January 2026. Pro-Linux.de published multiple advisories covering libsoup patches across SUSE, Fedora, and other distributions. The OpenSUSE project included the fix in its January 2026 Tumbleweed monthly update summary. Community reaction was moderate, with attention focused on the broad deployment of libsoup across GNOME-based systems and the default enablement of NTLM in several major applications (RedPacketSecurity).
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
libsoup2.4
devel
libsoup2.4
focal (esm-infra)
libsoup2.4
jammy
libsoup2.4
jammy (esm-apps)
libsoup3
noble
libsoup2.4
resolute
libsoup2.4
resolute (esm-apps)
libsoup2.4
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."