Security Advisory Desk
unratedQCS priority 76/100Ubuntu

USN-8890-1: libsoup vulnerabilities

Multiple security vulnerabilities were found in libsoup, an HTTP client/server library used in Ubuntu. These vulnerabilities could allow remote attackers to cause denial of service, gain unauthorized access to sensitive information, bypass security controls, or potentially execute arbitrary code. The issues affect several Ubuntu Long Term Support (LTS) versions, including 22.04, 24.04, and 26.04. Correcting these problems requires updating libsoup packages to fixed versions provided by Ubuntu.

QCS published 7/10/2026, 8:14:25 am ISTVendor disclosure 6/10/2026, 10:13:00 pm ISTVerified 7/10/2026, 8:51:40 am ISTRevision 1

In plain language

What this advisory means

Multiple security vulnerabilities were found in libsoup, an HTTP client/server library used in Ubuntu. These vulnerabilities could allow remote attackers to cause denial of service, gain unauthorized access to sensitive information, bypass security controls, or potentially execute arbitrary code. The issues affect several Ubuntu Long Term Support (LTS) versions, including 22.04, 24.04, and 26.04. Correcting these problems requires updating libsoup packages to fixed versions provided by Ubuntu.

Technical explanation

How the issue affects the environment

Libsoup improperly handled various HTTP/2 requests, HTTPS proxy connections, chunked HTTP requests, proxy authentication credentials, HTTP Range headers, and HTTP/2 transfers. These incorrect handling methods include parsing flaws, authentication mishandling, and protocol implementation errors. The vulnerabilities, identified by CVE identifiers CVE-2026-4271, CVE-2026-5119, CVE-2026-6324, CVE-2026-66339, CVE-2026-77014, CVE-2026-77680, CVE-2026-85197, and CVE-2026-85534, could be exploited remotely to cause denial of service, information disclosure, security control bypass, or arbitrary code execution in affected Ubuntu LTS releases.

Operational impact

Why teams should care

If exploited, these vulnerabilities could disrupt service availability or lead to unauthorized access and data leakage, impacting organizational operations and reputation. Arbitrary code execution risks may further compromise system integrity and confidentiality. Organizations running affected Ubuntu LTS versions should prioritize remediation to maintain secure and reliable services.

Immediate action

Update the libsoup packages on affected Ubuntu systems to the versions provided by Ubuntu Security Notices for your specific Ubuntu LTS release. Use the standard system update mechanisms to apply these fixes, ensuring to verify the package versions post-update. For some updates, fixes are available via Ubuntu Pro and Extended Security Maintenance (ESM). Regularly verify updates and remain attentive to additional releases from the vendor.

Affected and fixed releases

Affected versionsUbuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 26.04 LTS
Fixed versionsgir1.2-soup-2.4 2.74.3-6ubuntu1.9 (24.04 LTS), gir1.2-soup-2.4 2.74.3-10.1ubuntu5+esm3 (26.04 LTS), gir1.2-soup-3.0 3.4.4-5ubuntu0.9 (24.04 LTS), gir1.2-soup-3.0 3.6.6-1ubuntu0.1 (26.04 LTS), libsoup-2.4-1 2.74.3-6ubuntu1.9 (24.04 LTS), libsoup-2.4-1 2.74.3-10.1ubuntu5+esm3 (26.04 LTS), libsoup-3.0-0 3.4.4-5ubuntu0.9 (24.04 LTS), libsoup-3.0-0 3.6.6-1ubuntu0.1 (26.04 LTS)

Temporary risk reduction

The source does not specify any workarounds for these vulnerabilities.

Evidence and validation checklist

  • Ubuntu Security Notice USN-8890-1 published 2026-10-06
  • Descriptions of incorrect handling in libsoup causing potential denial of service, information disclosure, security bypass, and code execution
  • Specified affected Ubuntu releases and respective CVEs
  • Update instructions with fixed package versions per Ubuntu LTS release

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source