CVE-2025-46420

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 24, 2025
Updated: May 13, 2025
CWE ID 401

Summary

CVE-2025-46420 is a newly identified vulnerability affecting the libsoup library. This issue arises from a memory leak in the soup_header_parse_quality_list() function, which is responsible for parsing Quality lists. When encountering a Quality list containing only elements with all zeroes, this function fails to properly manage memory resources, leading to a memory leak. This can potentially be exploited by attackers to consume large amounts of memory, resulting in denial-of-service (DoS) conditions or other unwanted side effects. System administrators are advised to update their installations of libsoup as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share