CVE-2025-2784

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Apr 3, 2025
Updated: Apr 7, 2025
CWE ID 912

Summary

CVE-2025-2784 is a newly discovered vulnerability affecting the libsoup package. This issue allows an attacker to craft a malicious HTTP response that triggers a heap buffer over-read when the skip_insight_whitespace() function is used for content sniffing. Libsoup clients are at risk of reading one byte out of bounds, potentially leading to arbitrary code execution or memory corruption. The vulnerability poses a serious threat, as it can be exploited by untrusted HTTP servers. It is strongly recommended that users update their libsoup packages to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share