Impact
A flaw in Libsoup’s SoupServer allows an HTTP/1.x client to send an "Expect: 100-continue" request with a body that is not fully read or the connection is not closed before the server sends a final non‑1xx response. Because the leftover bytes are interpreted as a new HTTP request on a keep‑alive connection, a remote, unauthenticated attacker can place a complete HTTP request in that body and have SoupServer process the smuggled request. This results in unintended request handling, which could allow the attacker to issue operations the server does not intend for them to perform. The vulnerability is an example of HTTP request smuggling (CWE‑444).
Affected Systems
The vulnerability affects Red Hat Enterprise Linux 6, 7, 8, 9, and 10 distributions that include Libsoup’s SoupServer component. All these systems are potentially exposed if the server is reachable from an untrusted network.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity, and there is no EPSS data available. The vulnerability is not listed in the CISA KEV catalog. A remote attacker can exploit the flaw from any network location that can reach SoupServer, provided the server accepts keep‑alive connections and sends early final responses with an "Expect" header. The attack does not require authentication or privileged access on the host; it only requires the ability to send crafted HTTP requests over the network. Because the workaround advises isolation of SoupServer or disabling connection reuse, the risk is reduced if those controls are in place.
OpenCVE Enrichment