← Vulnerability feed

Vulnerability record · CVE-2025-2784 · published 3 April 2025

CVE-2025-2784: Gnome libsoup out-of-bounds read vulnerability

Gnome · Libsoup

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.

6.5 CVSS 3.1 Medium EPSS 0.84% · top 43.7% CWE-125 · Out-of-bounds read
6.5CVSS 3.1 base score
0.84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
21Affected product versions listed by NVD
17References, 2 tagged exploit
30 Jun 2026Last modified by NVD

Description

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected products

21 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-2784 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-8720WebKit memory corruption allows code execution via crafted web contentWebKit contains multiple memory corruption issues in memory handling that are triggered when processing maliciously crafted web content. Successful e…KEVEPSS 1.6%analysed7.8CVE-2023-4911GNU C Library ld.so GLIBC_TUNABLES heap buffer overflowThe GNU C Library dynamic loader ld.so mishandles the GLIBC_TUNABLES environment variable, causing a heap-based buffer overflow and out-of-bounds wri…KEVEPSS 81%analysed7.8CVE-2022-0847Linux kernel pipe buffer flaw allows local privilege escalationThe flags member of the new pipe buffer structure was not properly initialized in copy_page_to_iter_pipe and push_pipe, so it could hold stale values…KEVEPSS 93%analysed7.8CVE-2022-0492Linux kernel cgroups v1 release_agent privilege escalation and container escapeThe Linux kernel's cgroup_release_agent_write in kernel/cgroup/cgroup-v1.c mishandles authorization, letting the cgroups v1 release_agent feature be …KEVEPSS 5.5%analysed9.8CVE-2019-17266Gnome libsoup out-of-bounds read vulnerabilitylibsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properl…EPSS 2.8%9.8CVE-2018-12910Gnome libsoup out-of-bounds read vulnerabilityThe get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.EPSS 4.2%9.8CVE-2017-2885Gnome libsoup out-of-bounds write vulnerabilityAn exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflo…EPSS 24%9.1CVE-2026-2369Gnome libsoup vulnerabilityA flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overr…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2025-2784), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.