---
title: "CVE-2026-0719\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-0719?format=md
keywords: index, follow
---

# CVE-2026-0719

Publication date 8 January 2026

Last updated 11 March 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.6 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2026-0719?format=md#impact-score)

Toggle side navigation

## Description

A flaw was identified in the NTLM authentication handling of the libsoup
HTTP library, used by GNOME and other applications for network
communication. When processing extremely long passwords, an internal size
calculation can overflow due to improper use of signed integers. This
results in incorrect memory allocation on the stack, followed by unsafe
memory copying. As a result, applications using libsoup may crash
unexpectedly, creating a denial-of-service risk.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2026-0719?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| libsoup2.4 | 26.04 LTS resolute | Vulnerable, fix deferred |
| 25.10 questing | Ignored end of life, was deferred [2026-03-11] |
| 25.04 plucky | Ignored end of life, was deferred [2026-03-11] |
| 24.04 LTS noble | Vulnerable, fix deferred |
| 22.04 LTS jammy | Vulnerable, fix deferred |
| 20.04 LTS focal | Vulnerable, fix deferred |
| 18.04 LTS bionic | Vulnerable, fix deferred |
| 16.04 LTS xenial | Vulnerable, fix deferred |
| libsoup3 | 26.04 LTS resolute | Vulnerable, fix deferred |
| 25.10 questing | Ignored end of life, was deferred [2026-03-11] |
| 25.04 plucky | Ignored end of life, was deferred [2026-03-11] |
| 24.04 LTS noble | Vulnerable, fix deferred |
| 22.04 LTS jammy | Vulnerable, fix deferred |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [hlibk](https://launchpad.net/~hlibk)

As of 2026-03-11, the upstream PR fixing this issue has not yet been
merged.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

8.6 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | Low |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.6 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0719)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-0719)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-0719)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-0719)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-0719>
* <https://access.redhat.com/security/cve/CVE-2026-0719>
