CVE-2026-102556
Received Received - Intake

WebSocket Pong Frame Heap Corruption in libsoup

Vulnerability report for CVE-2026-102556, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: redhat-SADP

Description

A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
libsoup libsoup *
gnome libsoup 3.7.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-843 The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in libsoup, a library for handling HTTP and WebSocket traffic. When a WebSocket Pong frame is received, the library incorrectly emits a signal with a GByteArray pointer instead of a GBytes object. This mismatch can lead to heap corruption or crashes if an application connects a handler expecting the correct GBytes API.

Detection Guidance

This vulnerability involves a signal handling issue in libsoup where a GByteArray pointer is incorrectly passed instead of a GBytes object. Detection requires checking for applications using libsoup with WebSocket connections and monitoring for crashes or heap corruption during WebSocket Pong frame handling.

Impact Analysis

If you use an application relying on libsoup for WebSocket communication, a remote attacker could exploit this flaw to crash the application or potentially execute arbitrary code on your system by sending a specially crafted Pong frame.

Compliance Impact

This vulnerability primarily impacts system availability and stability due to potential crashes or heap corruption from crafted WebSocket Pong frames. It has limited direct impact on confidentiality or integrity, which are key concerns for GDPR and HIPAA compliance. However, repeated crashes or service disruptions could indirectly affect compliance by impairing data processing or access controls required by these regulations.

Mitigation Strategies

Update libsoup to the latest patched version. If updating is not immediately possible, disable WebSocket connections in affected applications or implement strict input validation for WebSocket frames. Monitor for crashes or memory corruption as indicators of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102556. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart