CVE-2024-52530: Gnome Libsoup
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.
Affected products
- Gnome Libsoup: before 3.6.0 (fixed in 3.6.0)
Published 2024-11-11. Last modified 2026-06-17.