[CLSA-2026:1787732250] libsoup: Fix of CVE-2026-66338
Type:
security
Severity:
Important
Release date:
2026-08-26 08:17:47 UTC
Description:
- CVE-2026-66338: reject chunk-size lines that violate RFC 9112 (leading whitespace, sign prefix, "0x" prefix or trailing garbage) in soup_body_input_stream_read_chunked() to prevent HTTP request smuggling
CVEs fixed:
Updated packages:
  • libsoup-2.62.2-2.0.11.el7.tuxcare.els3.i686.rpm
    sha:791cb878d8c2e24dc1a6527b221a3f0cee348d000f320821b9a8ddf95386adff
  • libsoup-2.62.2-2.0.11.el7.tuxcare.els3.x86_64.rpm
    sha:14c07e03e92f5bd0a7146d5c1a6b719e81773381f2b51ff228f5e2780eaf8bb2
  • libsoup-devel-2.62.2-2.0.11.el7.tuxcare.els3.i686.rpm
    sha:b429ff9fec2616e186942545bb8b7a91f41d238f6aa51777f06136b9145434c2
  • libsoup-devel-2.62.2-2.0.11.el7.tuxcare.els3.x86_64.rpm
    sha:0ab00a0d42a40331bb855d3ebf0284497c32ed77aecb3e0468b453feca1b83b5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.