CVE-2026-3633Disclosure(gnome / enterprise_linux)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gnome enterprise_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Carriage Return Line Feed) injection, occurs because the method value is not properly escaped during request line construction, potentially leading to HTTP request injection.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • libsoup

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-17); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Products
enterprise_linuxlibsoup

6 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-17: 4Mentions · 2026-03-23: 1Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-17: 3Technical Details · 2026-03-23: 103-1703-23
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-174
Disclosure2General1Patch1
2026-03-231
Disclosure1
Full discourse5 posts
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-3633: Remote CRLF injection in GNOME libsoup lets attackers slip arbitrary headers into your HTTP requests. Patch or sanitize method values to shut it down. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-3633 #infosec #Linux #AppSec

    Post summary

    The advisory reports a CRLF injection flaw (CVE‑2026‑3633) in GNOME libsoup and recommends applying a patch or sanitizing HTTP method values.

    0100052
    54 followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🚨 Another day, another “just a method string” that turns into header smuggling. If your HTTP parsing is this trusting, Windows devs are gonna blame Windows… like it’s a driver problem. https://windowsforum.com/threads/cve-2026-3633-libsoup-crlf-injection-method-header-smuggling-risk.406527/ #CrlfInjection #HttpRequestSmuggling #Libsoup #Cve20263633 https://t.co/gUaGxvcPgL

    Post summary

    The tweet warns of a new CVE (CVE‑2026‑3633) involving CRLF injection and HTTP request smuggling in Libsoup, linking to a forum thread for discussion.

    000003
    1.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3633 A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional … https://www.cve.org/CVERecord?id=CVE-2026-3633

    Post summary

    The post announces that CVE‑2026‑3633 is a flaw in libsoup, enabling remote header injection via the method parameter of `soup_message_new()`. No PoC, exploit, patch, or exploitation evidence is provided.

    00000132
    56.8K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-3633 📊 Severity: 3.9 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3633 #CVE-2026-3633 #CVE #Low  #CyberSecurity #InfoSec https://t.co/Gj9qS8q1dn

    Post summary

    The tweet announces a new CVE (CVE-2026-3633) with basic severity information and a reference link, but offers no technical details, exploitation evidence, or mitigation guidance.

    0000039
    101 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3633 CRLF Injection Vulnerability in libsoup HTTP Request Header Processing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3633

    Post summary

    The content announces CVE‑2026‑3633 as a CRLF injection flaw in libsoup, but offers neither PoC nor exploitation details, patches, or evidence of active use.

    0000046
    4.0K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appgnomelibsoup---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--

Explore more