Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-103399

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Sep 30, 2026
Vendor unknown

Description

A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither drains the declared body bytes nor closes the connection. On a keep-alive connection, those leftover bytes are interpreted as a subsequent HTTP request. A remote, unauthenticated attacker can place a complete HTTP request in the body and cause SoupServer to process that smuggled request, leading to unintended request handling.

References