CVE-2026-1761Disclosure

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to memory corruption. This issue may result in application crashes or arbitrary code execution in applications that process untrusted server responses, and it does not require authentication or user interaction.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-02-02); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-02: 3Mentions · 2026-02-03: 1Mentions · 2026-03-01: 1PoC Mentioned / Linked · 2026-02-03: 1Patch / Workaround · 2026-03-01: 1Technical Details · 2026-02-02: 3Technical Details · 2026-02-03: 1Technical Details · 2026-03-01: 102-0202-0303-01
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-023
Disclosure2General1
2026-02-031
Disclosure1
2026-03-011
Patch1
Full discourse5 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1761: HIGH] Stack-based buffer overflow flaw discovered in libsoup allows remote attackers to exploit it by sending crafted HTTP responses, leading to memory corruption and possible code execution.#cve,CVE-2026-1761,#cybersecurity https://cvefind.com/CVE-2026-1761

    Post summary

    A newly identified stack‑based buffer overflow in libsoup (CVE-2026-1761) can enable remote attackers to send crafted HTTP responses that lead to memory corruption and potential code execution.

    1000093
    583 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical vulnerability patched in #openSUSE Leap 16.0: CVE-2026-1761 in libsoup2. This is a CVSS 9.2 stack-based buffer overflow in multipart response parsing, leading to potential RCE. Read more: 👉 https://tinyurl.com/2r2cr9xe #Security https://t.co/9nBrUdjbgm

    Post summary

    OpenSUSE Leap 16.0’s libsoup2 CVE-2026-1761, a CVSS 9.2 stack‑based buffer overflow that could lead to RCE, has been patched. Additional information can be accessed via the provided link.

    0000080
    1.3K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A stack-based buffer overflow (CVE-2026-1761) affects libsoup2.4 during multipart HTTP response parsing. Review applications processing untrusted HTTP multipart data. #libsoup24 #bufferoverflow #infosec https://www.pulsepatch.io/posts/cve-2026-1761-libsoup24-buffer-overflow

    Post summary

    A stack-based buffer overflow in libsoup2.4 (CVE-2026-1761) affecting multipart HTTP response parsing is disclosed with a link for further details.

    0000043
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1761 Stack-Based Buffer Overflow in libsoup Multipart HTTP Response Parsing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1761

    Post summary

    A concise note about a stack‑based buffer overflow in libsoup’s multipart HTTP response parser, with a link to more information but no further detail on exploitation or mitigation.

    0000070
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1761 - High A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can ... https://www.thehackerwire.com/vulnerability/CVE-2026-1761/ https://t.co/JwhMVxaafD

    Post summary

    The text discloses CVE-2026-1761 as a stack‑based buffer overflow in libsoup, detailing the vulnerability mechanism but not providing PoC, exploit code, or patch information.

    0000048
    113 followersView on X

Explore more