Description
A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither drains the declared body bytes nor closes the connection. On a keep-alive connection, those leftover bytes are interpreted as a subsequent HTTP request. A remote, unauthenticated attacker can place a complete HTTP request in the body and cause SoupServer to process that smuggled request, leading to unintended request handling.
Published: 2026-09-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: HTTP request smuggling leading to unintended request processing
Action: Apply Mitigation
AI Analysis

Impact

A flaw in Libsoup’s SoupServer allows an HTTP/1.x client to send an "Expect: 100-continue" request with a body that is not fully read or the connection is not closed before the server sends a final non‑1xx response. Because the leftover bytes are interpreted as a new HTTP request on a keep‑alive connection, a remote, unauthenticated attacker can place a complete HTTP request in that body and have SoupServer process the smuggled request. This results in unintended request handling, which could allow the attacker to issue operations the server does not intend for them to perform. The vulnerability is an example of HTTP request smuggling (CWE‑444).

Affected Systems

The vulnerability affects Red Hat Enterprise Linux 6, 7, 8, 9, and 10 distributions that include Libsoup’s SoupServer component. All these systems are potentially exposed if the server is reachable from an untrusted network.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity, and there is no EPSS data available. The vulnerability is not listed in the CISA KEV catalog. A remote attacker can exploit the flaw from any network location that can reach SoupServer, provided the server accepts keep‑alive connections and sends early final responses with an "Expect" header. The attack does not require authentication or privileged access on the host; it only requires the ability to send crafted HTTP requests over the network. Because the workaround advises isolation of SoupServer or disabling connection reuse, the risk is reduced if those controls are in place.

Generated by OpenCVE AI on September 30, 2026 at 19:16 UTC.

Remediation

Vendor Workaround

To mitigate this do not expose SoupServer to untrusted networks; prefer terminating proxies or internal-only listeners. If SoupServer must sit behind a reverse proxy, disable backend connection reuse/pooling across clients so an undrained body cannot prepend to another client's request.


OpenCVE Recommended Actions

  • Configure SoupServer so it does not listen on untrusted networks; use a terminating proxy or keep the service internal-only
  • If SoupServer runs behind a reverse proxy, disable backend connection reuse or pooling across clients to prevent leftover request bodies from being interpreted as new requests
  • Upgrade Libsoup or apply any vendor‑released patch that addresses the improper handling of "Expect: 100-continue" bodies and ensures connections are closed or bodies are drained after early final responses

Generated by OpenCVE AI on September 30, 2026 at 19:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither drains the declared body bytes nor closes the connection. On a keep-alive connection, those leftover bytes are interpreted as a subsequent HTTP request. A remote, unauthenticated attacker can place a complete HTTP request in the body and cause SoupServer to process that smuggled request, leading to unintended request handling.
Title Libsoup: soupserver: http/1 request smuggling via undrained expect: 100-continue body
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-444
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-30T19:11:12.971Z

Reserved: 2026-09-30T14:31:37.532Z

Link: CVE-2026-103399

cve-icon Vulnrichment

Updated: 2026-09-30T19:11:08.587Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T18:18:16.137

Modified: 2026-09-30T20:17:30.987

Link: CVE-2026-103399

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-29T00:00:00Z

Links: CVE-2026-103399 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T19:30:18Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')