[Git][security-tracker-team/security-tracker][master] Add CVE-2026-12548/libsoup
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Jul 25 07:02:44 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6484e22e by Salvatore Bonaccorso at 2026-07-25T08:02:04+02:00
Add CVE-2026-12548/libsoup
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -4767,7 +4767,11 @@ CVE-2026-15342 (Plane contains a multi\u2011tenant authorization flaw in its ass
CVE-2026-15145 (The Essential Addons for Elementor \u2013 Popular Elementor Templates ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12548 (A heap out-of-bounds read flaw was found in libsoup. When parsing mult ...)
- TODO: check
+ - libsoup3 <unfixed>
+ - libsoup2.4 <removed>
+ NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/512
+ NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/524
+ NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/commit/7334c38f1f6aa5e64207cb415cf2509838c52b37 (3.7.1)
CVE-2026-12547 (SoupAuthManager caches proxy authentication credentials without scopin ...)
TODO: check
CVE-2026-11876 (In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/st ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6484e22e96192c0ebcffd4e3efc5e6e19bfe89f9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6484e22e96192c0ebcffd4e3efc5e6e19bfe89f9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260725/649a1d6e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list