MEDIUMVulnerability

CVE-2026-66337

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-66337
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
published_at
2026-07-24T23:16:51.760
last_modified
2026-08-24T16:44:56.007

Related Entities (8)

HAS_WEAKNESS (1)

[Weakness]Out-of-bounds Read

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (6)

[Product]
[Product]
[Product]
[Product]
[Product]
[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-66337 — Ninja Signal Threat Intelligence | Ninja Signal