Hi,
The following vulnerability was published for libsoup3.
CVE-2026-77680[0]:
| An algorithmic complexity flaw exists in libsoup's HTTP Range header
| processing that persists after the CVE-2025-32907 fix.
| CVE-2025-32907 addressed memory amplification when a client repeated
| the same range many times in a single Range header. Commit 9bb92f7a
| corrected merge correctness in
| soup_message_headers_get_ranges_internal() in libsoup/soup-message-
| headers.c, but the coalescing loop still removes merged ranges using
| g_array_remove_index() for each coalesced element. Because GArray is
| contiguous, each mid-array removal performs an O(N) memmove. When
| many identical satisfiable ranges are supplied (for example
| bytes=0-0 repeated thousands of times), the loop performs O(N²) work
| coalescing them into a single range. The vulnerable path is
| reachable server-side from handle_partial_get() in
| libsoup/server/http1/soup-server-message-io-http1.c when a
| SoupServer handler returns HTTP 200 with a non-empty body. No
| authentication is required. The number of ranges is bounded only by
| the maximum request header size (~100 KiB), allowing roughly 25,000
| ranges per request. Reporter measurements on libsoup HEAD containing
| the CVE-2025-32907 fix show ~90 ms single-core CPU per such request
| at the wire maximum, blocking the server's event loop for that
| duration. This is a CPU exhaustion / availability issue only. No
| memory corruption or information disclosure occurs. Affected:
| libsoup versions containing the CVE-2025-32907 fix but not merge
| request !550. Fixed upstream: MR !550 merged 2026-08-20, replacing
| per-element removal with O(N) in-place compaction and rejecting
| Range headers requesting more than 200 ranges. Upstream report:
| https://gitlab.gnome.org/GNOME/libsoup/-/issues/538 Related:
| CVE-2025-32907
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-77680
https://www.cve.org/CVERecord?id=CVE-2026-77680
[1] https://gitlab.gnome.org/GNOME/libsoup/-/issues/538
[2] https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/550
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore