Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this do not expose SoupServer to untrusted networks; prefer terminating proxies or internal-only listeners. If SoupServer must sit behind a reverse proxy, disable backend connection reuse/pooling across clients so an undrained body cannot prepend to another client's request.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither drains the declared body bytes nor closes the connection. On a keep-alive connection, those leftover bytes are interpreted as a subsequent HTTP request. A remote, unauthenticated attacker can place a complete HTTP request in the body and cause SoupServer to process that smuggled request, leading to unintended request handling. | |
| Title | Libsoup: soupserver: http/1 request smuggling via undrained expect: 100-continue body | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-444 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-30T17:42:31.307Z
Reserved: 2026-09-30T14:31:37.532Z
Link: CVE-2026-103399
No data.
Status : Received
Published: 2026-09-30T18:18:16.137
Modified: 2026-09-30T18:18:16.137
Link: CVE-2026-103399
No data.
OpenCVE Enrichment
No data.