CVE-2026-102557
Received Received - Intake

Heap Corruption in libsoup WebSocket Message Handling

Vulnerability report for CVE-2026-102557, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: redhat-SADP

Description

A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits of the underlying buffer type. A remote peer could send fragments that caused size truncation while the implementation still used the full length, leading to heap corruption or a crash.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
libsoup libsoup *
gnome libsoup 3.7.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a flaw in libsoup, a library for handling WebSocket messages. When fragmented WebSocket messages are reassembled into a GByteArray, libsoup did not properly limit the total message size to match the buffer type's capacity. A remote peer can send fragments that cause size truncation while the implementation still uses the full length, leading to heap corruption or a crash.

Detection Guidance

To detect this vulnerability, monitor for crashes or heap corruption in applications using libsoup WebSocket handling. Check logs for abnormal termination of libsoup-based services. Use network monitoring tools to inspect WebSocket traffic for unusually large fragmented messages.

Impact Analysis

An unauthenticated remote WebSocket peer could exploit this to cause heap corruption or denial of service during message reassembly. This may crash applications using libsoup WebSockets with untrusted peers. The impact is high availability disruption, with low confidentiality and integrity risks.

Mitigation Strategies

Immediately update libsoup to version 3.7.3 or later. If updating is not possible, set conservative limits on incoming WebSocket message sizes and avoid accepting WebSocket connections from untrusted peers. Disable WebSocket functionality if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102557. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart