CVE-2026-0719

Public on 2026-01-08
Modified on 2026-01-12
Description
A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can overflow due to improper use of signed integers. This results in incorrect memory allocation on the stack, followed by unsafe memory copying. As a result, applications using libsoup may crash unexpectedly, creating a denial-of-service risk.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.8
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core libsoup 2026-02-05 ALAS2-2026-3141 Fixed
Amazon Linux 2023 libsoup 2026-02-05 ALAS2023-2026-1392 Fixed
Amazon Linux 2023 libsoup3 2026-02-05 ALAS2023-2026-1393 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H