CVE-2024-52530: High severity debian/libsoup2.4 vulnerability
GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52530?
CVE-2024-52530 is classified as a critical vulnerability due to its potential for HTTP request smuggling.
How do I fix CVE-2024-52530?
To fix CVE-2024-52530, upgrade to libsoup version 3.6.1-1 or later.
Which versions of libsoup are affected by CVE-2024-52530?
CVE-2024-52530 affects libsoup versions prior to 3.6.0, particularly libsoup2.4 and libsoup3 versions up to 3.2.2-2.
Is CVE-2024-52530 applicable to Debian users?
Yes, Debian users running affected versions of libsoup should upgrade to mitigate CVE-2024-52530.
What type of attack can CVE-2024-52530 facilitate?
CVE-2024-52530 can facilitate HTTP request smuggling attacks, potentially allowing malicious requests to bypass security controls.