A flaw was found in libsoup, where the soupmessageheadersgetcontent_disposition() function is vulnerable to a NULL pointer dereference. This flaw allows a malicious HTTP peer to crash a libsoup client or server that uses this function.
{
"cwe_ids": [
"CWE-476"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32913.json",
"cna_assigner": "redhat"
}"2026-05-01T23:38:34Z"
[
{
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"281936149324709056643396573617539596701",
"37306503631334137803149435341106799958",
"81340554500924600413249182364185110231",
"288209360692215489362252233406715107748"
]
},
"id": "CVE-2025-32913-59f62549",
"signature_type": "Line",
"target": {
"file": "libsoup/auth/soup-auth-digest.c"
},
"source": "https://gitlab.gnome.org/gnome/libsoup@ea16eeacb052e423eb5c3b0b705e5eab34b13832",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"function_hash": "193447911690467284479937608647285939307",
"length": 393.0
},
"id": "CVE-2025-32913-fab21130",
"signature_type": "Function",
"target": {
"file": "libsoup/auth/soup-auth-digest.c",
"function": "soup_auth_digest_finalize"
},
"source": "https://gitlab.gnome.org/gnome/libsoup@ea16eeacb052e423eb5c3b0b705e5eab34b13832",
"deprecated": false
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-32913.json"