[Git][security-tracker-team/security-tracker][master] CVE-2026-12547: Add new libsoup issue

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 26 14:20:23 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e643b4ed by Salvatore Bonaccorso at 2026-07-26T15:19:53+02:00
CVE-2026-12547: Add new libsoup issue

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6199,7 +6199,9 @@ CVE-2026-12548 (A heap out-of-bounds read flaw was found in libsoup. When parsin
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/524
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/commit/7334c38f1f6aa5e64207cb415cf2509838c52b37 (3.7.1)
 CVE-2026-12547 (SoupAuthManager caches proxy authentication credentials without scopin ...)
-	TODO: check
+	- libsoup3 <unfixed>
+	- libsoup2.4 <removed>
+	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/506
 CVE-2026-11876 (In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/st ...)
 	TODO: check
 CVE-2025-68640 (The Apple Find My backend service through 2025-12-17 allows an attacke ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e643b4ed487b8a30c48e9ed067e0e78e28223e91

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e643b4ed487b8a30c48e9ed067e0e78e28223e91
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/399c5f78/attachment.htm>


More information about the debian-security-tracker-commits mailing list