CVE-2025-32907
MEDIUMDescription
A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.
CVSS v3.1 Score
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2025-32907? +
How severe is CVE-2025-32907? +
How do I check if I'm vulnerable to CVE-2025-32907? +
Related Vulnerabilities
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to …
The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could …
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to …