CVE-2026-102555
Received Received - Intake

libsoup NUL-Terminated Base64 Data-URI Decoding Flaw

Vulnerability report for CVE-2026-102555, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: redhat-SADP

Description

A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when processing a crafted data URI.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
gnome libsoup 3.7.3
gnome libsoup to 3.7.3 (exc)
gnome libsoup3 to 3.7.3 (exc)
gnome libsoup *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a heap buffer overflow in libsoup's soup_uri_decode_data_uri() function. It occurs when processing base64 data-URI payloads. The function incorrectly treats the payload as a NUL-terminated string, leading to uninitialized length variables if the payload contains embedded NUL bytes. This can cause out-of-bounds memory reads or application crashes.

Detection Guidance

To detect this vulnerability, check the version of libsoup installed on your system. Run 'rpm -qa | grep libsoup' on RPM-based systems or 'dpkg -l | grep libsoup' on Debian-based systems. Compare the version against the fixed version 3.7.3. Additionally, monitor application logs for crashes or memory corruption errors when processing data URIs.

Impact Analysis

An attacker could exploit this flaw to cause denial of service by crashing applications or read sensitive memory contents. This affects applications using libsoup or libsoup3, especially in environments like GNOME or HTTP clients where libsoup is commonly used.

Mitigation Strategies

Immediately update libsoup to version 3.7.3 or later. If updating is not possible, avoid using untrusted data URIs in applications that use libsoup. Monitor for crashes or memory corruption errors in applications processing data URIs. Consider disabling data URI processing in affected applications as a temporary workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102555. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart