HIGHVulnerability

CVE-2026-85197

A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution.

Properties

severity
HIGH
score
7.6
cve_id
CVE-2026-85197
signal_observed_at
2026-09-16T21:37:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
published_at
2026-09-04T08:17:16.677
last_modified
2026-09-16T18:17:17.720

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Use After Free

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85197 — Ninja Signal Threat Intelligence | Ninja Signal