CVE-2026-103399
Received Received - Intake

SoupServer HTTP Request Smuggling Vulnerability

Vulnerability report for CVE-2026-103399, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: redhat-SADP

Description

A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither drains the declared body bytes nor closes the connection. On a keep-alive connection, those leftover bytes are interpreted as a subsequent HTTP request. A remote, unauthenticated attacker can place a complete HTTP request in the body and cause SoupServer to process that smuggled request, leading to unintended request handling.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
libsoup soupserver *
gnome libsoup 3.7.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-444 The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an HTTP request smuggling vulnerability in libsoup's SoupServer component. When a client sends a request with an Expect: 100-continue header and a body, SoupServer may send a final response before reading the body. This leaves leftover bytes that get interpreted as a new request on a keep-alive connection, allowing an attacker to smuggle and execute hidden requests.

Detection Guidance

To detect this vulnerability, monitor for unexpected HTTP responses or requests that suggest request smuggling. Check for connections where SoupServer sends a final response before reading the full request body. Use network traffic analysis tools like tcpdump or Wireshark to inspect HTTP/1.x traffic for malformed or split requests. Look for patterns where a client sends an Expect: 100-continue header followed by leftover bytes interpreted as a new request.

Commands to check for vulnerable libsoup versions: rpm -q libsoup or dpkg -l libsoup. Inspect server logs for premature 4xx responses (e.g., 401) followed by 2xx responses from the same connection, which may indicate smuggled requests.

Impact Analysis

An attacker could send a crafted request that tricks SoupServer into processing unintended requests. This might lead to unauthorized actions, data leaks, or bypassing security controls. However, impact is limited for typical SoupServer use as it is not designed for hardened internet-facing deployments.

Compliance Impact

This vulnerability could potentially violate compliance requirements that mandate secure handling of HTTP requests, such as data integrity and access control. Unauthorized request processing may lead to data breaches or unauthorized access, which are critical concerns under GDPR and HIPAA.

Mitigation Strategies

Avoid exposing SoupServer to untrusted networks or the internet. Use terminating proxies or restrict SoupServer to internal-only listeners. If behind a reverse proxy, disable backend connection reuse or pooling across clients to prevent leftover bytes from affecting other requests.

Monitor for signs of exploitation, such as unexpected requests or responses. Apply patches once available from upstream libsoup maintainers. Consult vendor-specific guidance for Red Hat products, as mitigation steps may vary by version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103399. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart