CVE-2025-2784
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Summary
CVE-2025-2784 is a newly discovered vulnerability affecting the libsoup package. This issue allows an attacker to craft a malicious HTTP response that triggers a heap buffer over-read when the skip_insight_whitespace() function is used for content sniffing. Libsoup clients are at risk of reading one byte out of bounds, potentially leading to arbitrary code execution or memory corruption. The vulnerability poses a serious threat, as it can be exploited by untrusted HTTP servers. It is strongly recommended that users update their libsoup packages to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- ESP 3.2