Name
CVE-2024-52530
Description
GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.
CWEs
Published Date
Updated Date
Workaround
-
Analysis#
Vulnerability Ratings#
7.5
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
libsoup (buildroot:2025.02.x)
#
Title
Author
Resolve
1
headers: Strictly don't allow NUL bytes
Patrick Griffis <pgriffis@igalia.com>
CVE-2024-52530
libsoup (buildroot:master)
#
Title
Author
Resolve
1
headers: Strictly don't allow NUL bytes
Patrick Griffis <pgriffis@igalia.com>
CVE-2024-52530
libsoup (yocto:kirkstone)
#
Title
Author
Resolve
1
headers: Strictly don't allow NUL bytes
Patrick Griffis <pgriffis@igalia.com>
CVE-2024-52530
libsoup-2.4 (yocto:kirkstone)
#
Title
Author
Resolve
1
headers: Strictly don't allow NUL bytes
Patrick Griffis <pgriffis@igalia.com>
CVE-2024-52530
libsoup-2.4 (yocto:scarthgap)
#
Title
Author
Resolve
1
headers: Strictly don't allow NUL bytes
Patrick Griffis <pgriffis@igalia.com>
CVE-2024-52530