CVE-2026-102556

Summary

A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')

Workarounds

To mitigate avoid connecting custom handlers to SoupWebsocketConnection::pong, or avoid WebSocket use with untrusted peers.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References