CVE-2025-32909
Executive Summary
CVE-2025-32909 exposes a NULL pointer dereference in libsoup’s SoupContentSniffer during MP4 sniffing, potentially crashing the client when the HTTP server triggers the flaw. The issue is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 5.3 (MEDIUM) - Published: 2025-04-14T15:15:25.140 - Last Modified: 2026-09-15T18:17:11.720
Original Description: A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash.
"Let us revere, let us worship, but erect and open-eyed, the highest, not the lowest; the future, not the past!"
— Charlotte Gilman
Source: NVD