A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.
References
Configurations
No configuration.
History
28 Apr 2025, 11:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
Summary | (en) A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service. |
15 Apr 2025, 18:39
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
14 Apr 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-14 14:15
Updated : 2025-04-28 11:15
NVD link : CVE-2025-32907
Mitre link : CVE-2025-32907
CVE.ORG link : CVE-2025-32907
JSON object : View
Products Affected
No product.
CWE
CWE-1050
Excessive Platform Resource Consumption within a Loop