CVE-2026-102558

Summary

A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer overflow while reading frame data.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-125: Out-of-bounds Read

Workarounds

To mitigate this configure a finite max-incoming-payload-size (do not set it to 0/unlimited) on SoupWebsocketConnection. Restrict WebSocket exposure to trusted peers.

References