← Back to blog

Critical libsoup Vulnerabilities Expose Ubuntu Systems to DoS and Data Leaks

Multiple high-severity flaws in libsoup affect recent Ubuntu LTS versions, enabling denial of service and sensitive data exposure.

TL;DR

  • libsoup HTTP library has six new CVEs affecting Ubuntu 22.04–26.04 LTS.
  • Vulnerabilities allow remote DoS, credential leaks, and security control bypass.
  • Organizations using affected Ubuntu versions should patch immediately.
  • Issues stem from improper handling of HTTP/2, HTTPS proxies, and chunked requests.
  • CVEs include CVE-2026-4271, CVE-2026-5119, CVE-2026-6324, CVE-2026-66339, CVE-2026-77014, and CVE-2026-77680.

Ubuntu has released security updates addressing multiple critical vulnerabilities in the libsoup HTTP client/server library. These issues affect several supported long-term support releases and expose systems to denial of service, sensitive data leaks, and potential bypass of security mechanisms.

The flaws range from improper handling of HTTP/2 traffic to weaknesses in proxy authentication and chunked request parsing. Organizations running Ubuntu 22.04 through 26.04 LTS should prioritize applying the corresponding patches to mitigate these risks.

Denial of Service Risks

  • CVE-2026-4271 affects HTTP/2 request processing in Ubuntu 24.04 and 26.04, allowing attackers to crash services.
  • Two additional DoS vulnerabilities (CVE-2026-77014, CVE-2026-77680) relate to malformed HTTP Range headers across all affected versions.

Data Exposure and Authentication Concerns

  • CVE-2026-5119 impacts HTTPS proxy handling in Ubuntu 22.04–26.04, potentially leaking sensitive connection data.
  • Weakness in proxy authentication (CVE-2026-66339) may expose credentials to unauthorized parties.
  • Improper parsing of chunked HTTP requests (CVE-2026-6324) could allow attackers to evade input validation controls.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Critical libsoup Vulnerabilities Expose Ubuntu Systems to DoS and Data Leaks — Agent Breach Blog | Agent Breach