VDB

CVE-2026-85197

CVE-2026-85197 PUBLISHED CVSS 7.6 HIGH

Reported by redhat · Published September 4, 2026

A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution.

Risk Scores

CVSS 3.1
7.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux 100:3.6.5-3.el10_2.14
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 100:3.6.5-3.el10_2.14
Red HatRed Hat Enterprise Linux 6

Timeline

  • Sep 4, 2026 EPSS Score
  • Sep 4, 2026 Coalition ESS Score
  • Sep 4, 2026 CVE Published
  • Sep 5, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 CVE Updated
  • Sep 17, 2026 EPSS Score
  • Sep 17, 2026 Distribution Patch
  • Sep 17, 2026 Security Advisory
  • Sep 18, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›