1
websocket-test: disconnect error copy after the test ends
Ignacio Casal Quinteiro <qignacio@amazon.com>
2
soup-message-headers: Correct merge of ranges
Milan Crha <mcrha@redhat.com>
3
soup-date-utils: Add value checks for date/time parsing
Changqing Li <changqing.li@windriver.com>
4
multipart: Fix read out of buffer bounds under
Milan Crha <mcrha@redhat.com>
5
headers: Handle parsing only newlines
Patrick Griffis <pgriffis@igalia.com>
6
Fix using int instead of size_t for strcspn return
Patrick Griffis <pgriffis@igalia.com>
7
auth-digest: fix crash in
Changqing Li <changqing.li@windriver.com>
8
Backport auth tests for CVE-2025-32910
Andreas Henriksson <andreas@fatal.se>
9
soup-multipart: Verify boundary limits for multipart body
Milan Crha <mcrha@redhat.com>
10
headers: Be more robust against invalid input when
Patrick Griffis <pgriffis@igalia.com>
11
auth-digest: Handle missing nonce
Patrick Griffis <pgriffis@igalia.com>
12
auth-digest: Handle missing nonce
Patrick Griffis <pgriffis@igalia.com>
13
soup_message_headers_get_content_disposition: strdup
Patrick Griffis <pgriffis@igalia.com>
CVE-2025-32911
CVE-2025-32913
14
websocket-test: Disconnect error signal in another place
Simon McVittie <smcv@debian.org>
15
Fix heap buffer overflow in
Ar Jun <pkillarjun@protonmail.com>
16
websocket: process the frame as soon as we read data
Ignacio Casal Quinteiro <qignacio@amazon.com>
17
soup_header_parse_quality_list: Fix leak
Patrick Griffis <pgriffis@igalia.com>
18
auth-digest: Handle missing realm in authenticate header
Patrick Griffis <pgriffis@igalia.com>
19
digest-auth: Handle NULL nonce
Patrick Griffis <pgriffis@igalia.com>
20
auth-digest: Fix leak
Patrick Griffis <pgriffis@igalia.com>
21
content-sniffer: Handle sniffing resource shorter than 4
Patrick Griffis <pgriffis@igalia.com>
22
sniffer: Fix potential overflow
Patrick Griffis <pgriffis@igalia.com>
23
tests: Add test for passing invalid UTF-8 to
Patrick Griffis <pgriffis@igalia.com>
24
headers: Strictly don't allow NUL bytes
Patrick Griffis <pgriffis@igalia.com>
25
session: Strip authentication credentails on
Patrick Griffis <pgriffis@igalia.com>
26
soup_message_headers_get_content_disposition: Fix NULL deref
Patrick Griffis <pgriffis@igalia.com>
CVE-2025-32911
CVE-2025-32913
27
headers: Handle parsing edge case
Patrick Griffis <pgriffis@igalia.com>
28
meson.build: set c_std to gnu99
Fabrice Fontaine <fontaine.fabrice@gmail.com>
29
sniffer: Add better coverage of skip_insignificant_space()
Patrick Griffis <pgriffis@igalia.com>
30
Fix heap buffer overflow in soup_content_sniffer_sniff
Patrick Griffis <pgriffis@igalia.com>
31
soup-multipart: Verify array bounds before accessing its
Milan Crha <mcrha@redhat.com>