CVE detail
CVE-2026-12549
The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- https://gitlab.gnome.org/GNOME/libsoup/-/work_items/516gitlab.gnome.org
No excerpt available.
Exploitgitlab.gnome.orgJun 22, 2026, 4:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2489999bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJun 22, 2026, 4:16 PM - https://access.redhat.com/security/cve/cve-2026-0716access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 22, 2026, 4:16 PM - https://access.redhat.com/security/cve/CVE-2026-12549access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 22, 2026, 4:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-1767CVSS 5.6 · Medium
A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer over…
- CVE-2026-1766CVSS 5.6 · Medium
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerab…
- CVE-2026-34002CVSS 6.1 · Medium
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11…
- CVE-2019-19339CVSS 6.5 · Medium
It was found that the Red Hat Enterprise Linux 8 kpatch update did not include the complete fix for CVE-2018-12207. A flaw was found in the way Intel CPUs handle inconsistency bet…
- CVE-2026-2708CVSS 3.7 · Low
A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditiona…
- CVE-2026-5119CVSS 5.9 · Medium
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNEC…