Microsoft Security Response Center guidance
Vendor revision: Aug 12, 2026CBL-Mariner Releases
Vendor-listed releases
- 3.0.4-7
- 3.4.4-7
Vulnerability intelligence
CVE-2025-32907 and is rated Medium severity with a CVSS score of 5.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CBL-Mariner Releases
Vendor-listed releases
A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack.
This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.
Source: NVD