[Git][security-tracker-team/security-tracker][master] Add CVE-2026-12478/libsoup

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Jul 25 07:05:11 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e8a61dd9 by Salvatore Bonaccorso at 2026-07-25T08:04:39+02:00
Add CVE-2026-12478/libsoup

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -12348,7 +12348,11 @@ CVE-2026-12523 (Summary    Cloudflare quiche's HTTP/3 layer was discovered to be
 CVE-2026-12512 (The Quotes llama WordPress plugin before 3.1.6 does not properly sanit ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-12478 (The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the i ...)
-	TODO: check
+	- libsoup3 <unfixed>
+	[trixie] - libsoup3 <not-affected> (Fix for CVE-2026-0716 not applied)
+	[bookworm] - libsoup3 <not-affected> (Fix for CVE-2026-0716 not applied)
+	- libsoup2.4 <not-affected> (Fix for CVE-2026-0716 not applied)
+	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/518
 CVE-2026-12281 (The Shibboleth WordPress plugin before 2.5.4 does not fail closed when ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-11944 (openSIS Classic 9.3 contains an authenticated path traversal vulnerabi ...)
@@ -118818,6 +118822,7 @@ CVE-2026-0716 (A flaw was found in libsoup\u2019s WebSocket frame processing whe
 	[trixie] - libsoup2.4 <no-dsa> (Minor issue)
 	[bookworm] - libsoup2.4 <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/476
+	NOTE: When fixing this issue make sure to make the fix complete to not open up CVE-2026-12478
 CVE-2026-22587 (Ideagen DevonWay contains a stored cross site scripting vulnerability. ...)
 	NOT-FOR-US: Ideagen DevonWay
 CVE-2026-22522 (Missing Authorization vulnerability in Munir Kamal Block Slider block- ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8a61dd93425e33e7fddef135bd8c1f639deee8b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8a61dd93425e33e7fddef135bd8c1f639deee8b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260725/8a3dc5ee/attachment.htm>


More information about the debian-security-tracker-commits mailing list