CVE-2026-4271Disclosure(gnome / enterprise_linux)

LOWCVSS 7.5 · HIGH

Signal is active with 8 mentions in latest observed window

Immediate actions

  • Patch gnome enterprise_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2 requests that cause authentication failures. This can lead to the application attempting to access memory that has already been freed, potentially causing application instability or crashes, resulting in a Denial of Service (DoS).

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • libsoup

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • 8 total mentions across 1 day

Affected systems

Products
enterprise_linuxlibsoup

6 versions affected across 2 products

Deep dive

Activity timeline8 mentions / 1d
02468Mentions · 2026-03-17: 8Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-17: 703-17
Signal classification3 categories
Disclosure
675.0%
General
112.5%
Patch
112.5%
Referenced assets9 URLs
Full discourse8 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4271 A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote a… https://www.cve.org/CVERecord?id=CVE-2026-4271

    Post summary

    CVE‑2026‑4271 is a use‑after‑free flaw in libsoup’s HTTP/2 server implementation, with technical details disclosed but no PoC, exploit, or patch information available.

    00000131
    56.8K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4271 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4271 #CVE-2026-4271 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/eI7suBw1f3

    Post summary

    A new CVE (CVE-2026-4271) is announced with medium severity and risk, affecting unspecified products, but lacks detailed technical information, exploit details, or patch guidance.

    0000040
    101 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4271 - Libsoup: libsoup: denial of service via use-after-free in http/2 server Intel Report: https://ift.tt/XYoQTuU

    Post summary

    The bulletin reports a use‑after‑free denial‑of‑service vulnerability in Libsoup’s HTTP/2 server (CVE‑2026‑4271) but offers no proof‑of‑concept, exploit code, active use evidence, or patch details.

    0000050
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4271 - Libsoup: libsoup: denial of service via use-after-free in http/2 server Intel Report: https://ift.tt/CvHbO46

    Post summary

    An alert is issued for CVE‑2026‑4271, a denial‑of‑service use‑after‑free flaw in Libsoup’s HTTP/2 server, with a link to an Intel report for further details.

    0000075
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4271 - Libsoup: libsoup: denial of service via use-after-free in http/2 server Intel Report: https://ift.tt/fLC7Q05

    Post summary

    The alert announces CVE‑2026‑4271, a use‑after‑free denial‑of‑service bug in libsoup’s HTTP/2 server, and provides a link to an Intel report for more details.

    0000044
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4271 - Libsoup: libsoup: denial of service via use-after-free in http/2 server Intel Report: https://ift.tt/u6PZ7eo

    Post summary

    The alert announces CVE-2026-4271, describing a use‑after‑free denial‑of‑service flaw in Libsoup’s HTTP/2 server without any mention of exploitation, PoC, or patch.

    0000034
    336 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4271 Use-After-Free Vulnerability in libsoup HTTP/2 Server Enab... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4271 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A tweet alerts about CVE-2026-4271, identifying it as a Use-After-Free flaw in libsoup HTTP/2, but offers no PoC, exploit, active usage, or patch details.

    0000048
    4.0K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-4271: Remote use-after-free in libsoup’s HTTP/2 server lets anyone crash apps relying on it, knocking services offline. Update libsoup to the latest release or apply vendor patches. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-4271 #infosec #Linux #GNOME

    Post summary

    The tweet announces CVE-2026-4271, a remote use‑after‑free vulnerability in libsoup’s HTTP/2 server that can crash services, and urges users to update the library or apply vendor patches.

    0000063
    54 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appgnomelibsoup---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--

Explore more