
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1761 is a stack-based buffer overflow vulnerability in libsoup, the GNOME HTTP client/server library, affecting both the libsoup (2.x) and libsoup3 (3.x) branches. The flaw exists in the multipart HTTP response parsing logic — specifically in the soup_filter_input_stream_read_until() function — where an incorrect length calculation can cause more data to be written than the size of the caller-provided stack buffer. It was disclosed on February 2, 2026, and has a CVSS v3.1 base score of 8.6 (High) (Red Hat CVE, Red Hat Bugzilla).
The root cause is classified as CWE-121 (Stack-Based Buffer Overflow). The vulnerable code path is in soup_filter_input_stream_read_until(), where an incorrect length calculation during multipart/form-data response parsing allows more data to be copied into a fixed-size stack buffer than it can hold, resulting in memory corruption (Red Hat Bugzilla). The attack vector is network-based: a remote attacker controls a server (or performs a man-in-the-middle position) and sends a specially crafted multipart HTTP response to a client application using libsoup. No authentication or user interaction is required, and exploitation requires only that the target application processes HTTP responses from an attacker-controlled or compromised server (Red Hat CVE).
Successful exploitation can lead to memory corruption on the stack of the process using libsoup, resulting in application crashes (denial of service) or, in more severe cases, arbitrary code execution within the context of the affected application. Because libsoup is widely used by GNOME desktop applications and server-side components, the scope of affected assets is broad — any application that processes multipart HTTP responses from untrusted sources is at risk. Confidentiality impact is rated Low, integrity impact High, and availability impact Low per the CVSS scoring (Red Hat CVE).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.54%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures have been published by Nessus (Tenable) and Qualys scanners, indicating broad scanner coverage for identifying vulnerable systems.
soup_filter_input_stream_read_until(), causing the function to copy more data than the stack buffer can hold.soup_filter_input_stream_read_until in stack traces./var/crash or application working directories.Red Hat has released patched packages across multiple RHEL versions. Key errata include: RHSA-2026:1948 (RHEL 8.8), RHSA-2026:2005 (RHEL 9.2), RHSA-2026:2006 (RHEL 10.0 — libsoup3 3.6.5-3.el10_0.14), RHSA-2026:2007 (RHEL 9.4), RHSA-2026:2008 (RHEL 9.0), RHSA-2026:2049 (RHEL 9.6), RHSA-2026:2182 (RHEL 10), RHSA-2026:2214/2215/2216 (RHEL 8/9), and additional errata for RHEL 7 ELS and various update services (Red Hat Bugzilla). IBM has also released patches for affected Instana Observability (OnPrem) and Netezza Appliance products. Administrators should update libsoup and libsoup3 packages to the latest patched versions immediately; no configuration-based workaround is available, so patching is the only remediation.
The vulnerability received coverage from security news outlets including The Hacker Wire, which published an article on the libsoup stack overflow RCE risk from malformed HTTP responses (The Hacker Wire). The CISA weekly vulnerability bulletin for the week of February 2, 2026 included CVE-2026-1761. Multiple Linux distribution security teams (Red Hat, SUSE, openSUSE, AlmaLinux, Rocky Linux, Oracle Linux, Amazon Linux) issued advisories and patches in rapid succession following disclosure, reflecting the broad impact of libsoup across the Linux ecosystem.
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
libsoup2.4
devel
libsoup2.4
focal (esm-infra)
libsoup2.4
jammy
libsoup2.4
jammy (esm-apps)
libsoup3
noble
libsoup2.4
resolute
libsoup2.4
resolute (esm-apps)
libsoup2.4
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."