CVE-2026-102558
Received Received - Intake

Heap Buffer Overflow in libsoup Due to Unlimited Payload Size

Vulnerability report for CVE-2026-102558, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: redhat-SADP

Description

A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer overflow while reading frame data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
gnome libsoup to 3.7.3 (inc)
libsoup libsoup *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap buffer overflow vulnerability in libsoup, a library for HTTP and WebSocket communication. When the max-incoming-payload-size is set to unlimited (0), an attacker can send a very large WebSocket frame that causes the incoming buffer to grow beyond its allocated size. This leads to heap corruption or denial of service by writing past the buffer's memory.

Detection Guidance

Check if libsoup is installed and its version using commands like 'rpm -q libsoup' or 'dpkg -l libsoup'. Monitor WebSocket traffic for unusually large payloads or crashes in applications using libsoup. Inspect logs for heap corruption errors or application segmentation faults.

Impact Analysis

An attacker could exploit this to read sensitive memory such as cryptographic keys or personal data, bypass security mechanisms like ASLR, or crash the application causing a denial of service. The impact depends on the application's use of libsoup and whether payload size limits are disabled.

Mitigation Strategies

Set a finite max-incoming-payload-size in libsoup configurations to prevent unlimited buffer growth. Restrict WebSocket connections to trusted peers only. Upgrade libsoup to version 3.7.3 or later if available. Apply vendor patches or mitigations as recommended by Red Hat or other vendors.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102558. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart