Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this set a conservative max-total-incoming-message-size / incoming payload limits where the API allows, and do not accept WebSocket connections from untrusted peers.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits of the underlying buffer type. A remote peer could send fragments that caused size truncation while the implementation still used the full length, leading to heap corruption or a crash. | |
| Title | Libsoup: libsoup: heap buffer overflow during websocket message reassembly | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-29T17:15:25.792Z
Reserved: 2026-09-29T13:19:12.882Z
Link: CVE-2026-102557
No data.
Status : Awaiting Analysis
Published: 2026-09-29T17:17:06.600
Modified: 2026-09-29T21:29:07.663
Link: CVE-2026-102557
No data.
OpenCVE Enrichment
No data.