[CLSA-2026:1787751026] libsoup: Fix of CVE-2026-66338
Type:
security
Severity:
Important
Release date:
2026-08-26 14:18:45 UTC
Description:
- CVE-2026-66338: reject chunk-size lines that violate RFC 9112 (leading whitespace, sign prefix, "0x" prefix or trailing garbage) in soup_body_input_stream_read_chunked() to prevent HTTP request smuggling
CVEs fixed:
Updated packages:
  • libsoup-2.62.2-2.0.11.el7.tuxcare.els3.i686.rpm
    sha:cc3ac470332d4d345c846ad2086e780776941ef1061755fdbed05f1690045f20
  • libsoup-2.62.2-2.0.11.el7.tuxcare.els3.x86_64.rpm
    sha:319917dd3e6cf9fb5d31e266b7e8ada129cfc1610e76ce559467d978e8c99b1b
  • libsoup-devel-2.62.2-2.0.11.el7.tuxcare.els3.i686.rpm
    sha:60b7a03cfb9214e8a8802bfbd4613cc0927ff8c42cc39a46d4eb2ba73e0dff6d
  • libsoup-devel-2.62.2-2.0.11.el7.tuxcare.els3.x86_64.rpm
    sha:e54292dcc3daef3bf9f6ff2baa18aba1098cd6bf77ab68ec2ef1e42f5697ab9d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.