CVE-2025-32907
A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.66%
- CWE
- CWE-1050
- Published
- 2025-04-14
- Last modified
- 2026-06-30
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
- Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support
- Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support
Weakness type
Related vulnerabilities
- CVE-2026-52681 — Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid...
- CVE-2026-71488 — league/commonmark: Quadratic-time denial of service when parsing crafted Markdown
- CVE-2026-4634 — Keycloak: keycloak: denial of service via excessive processing of openid connect scope parameters
- CVE-2026-22263 — Suricata http1: quadratic complexity in headers parsing over multiple packets
- CVE-2026-22261 — Suricata eve/alert: http1 xff handling can lead to denial of service
- CVE-2025-48866 — ModSecurity has possible DoS vulnerability in sanitiseArg action
- CVE-2025-47947 — ModSecurity Has Possible DoS Vulnerability
- CVE-2024-4068 — Memory Exhaustion in braces