CVE-2025-32910

Executive Summary

CVE-2025-32910: libsoup's soup_auth_digest_authenticate() contains a NULL pointer dereference that can cause the client to crash, leading to a denial‑of‑service condition. The flaw is not yet listed in CISA KEV. No known exploitation beyond crash, but any application using libsoup may be impacted.


Authoritative CVE Metadata - CVSS Base Score: 6.5 (MEDIUM) - Published: 2025-04-14T15:15:25.307 - Last Modified: 2026-09-15T18:17:11.890

Original Description: A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.

"The industrial landscape is already littered with remains of once successful companies that could not adapt their strategic vision to altered conditions of competition."

— Abernathy
Source: NVD