[CLSA-2026:1787732034] libsoup: Fix of CVE-2026-66338
Type:
security
Severity:
Important
Release date:
2026-08-26 08:14:10 UTC
Description:
- CVE-2026-66338: reject chunk-size lines that violate RFC 9112 (leading whitespace, sign prefix, "0x" prefix or trailing garbage) in soup_body_input_stream_read_chunked() to prevent HTTP request smuggling
CVEs fixed:
Updated packages:
  • libsoup-2.62.2-2.0.11.el7.tuxcare.els3.i686.rpm
    sha:d973924bae786def85ae07f566bde845bb7012978daded0f99477c4978c569d8
  • libsoup-2.62.2-2.0.11.el7.tuxcare.els3.x86_64.rpm
    sha:a2651f18401acf43d2a01ea9d764a997680201feef151335f1621fc1cb7bc087
  • libsoup-devel-2.62.2-2.0.11.el7.tuxcare.els3.i686.rpm
    sha:4cc49b20f6fea62016e7890885e7c451155618fdd2b93040ec32967546a365f2
  • libsoup-devel-2.62.2-2.0.11.el7.tuxcare.els3.x86_64.rpm
    sha:309fa0d453ce7430428c0dd019304e0860c24df41d0764d8fab133336876df2c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.