CVE-2026-77014CWE-197

CVE-2026-77014

Medium · published August 20, 2026

CVSS v3.1
5.3
EPSS
0%
Percentile
14.0
In the wild
Unconfirmed
What it is

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00232 · 14.0th percentile
Weakness
CWE-197 · Numeric Truncation Error
Published
2026-08-20T13:16Z
References (3)
EPSS history
Timeline
  • 20 AUG 08:21Z
    Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of http range responses
    cvelistv5