Skip to content
CVE Alert: CVE-2026-102560 – Red Hat

CVE Alert: CVE-2026-102560 – Red Hat

Redpacketsecurity •admin • September 29, 2026

A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could wrap, causing zlib to write past the allocated buffer and resulting in a heap buffer overflow.

**Risk verdict:** Treat this as urgent on internet-reachable systems that use WebSocket compression; exploitation status and prioritisation flags were not supplied, so confirmed exploitation cannot be established.

**Why this matters:** A successful trigger can corrupt heap memory and is most likely to disrupt the affected process or service. Memory corruption can sometimes have consequences beyond a crash, but the available impact assessment indicates availability is the main concern; do not assume remote code execution without further evidence.

**Most likely attack path:** A remote party sends traffic that causes an affected application to emit a very large WebSocket message while per-message compression is enabled. The metrics indicate no authentication or user action is required and the trigger is not complex, although the attacker must reach a code path that generates such an outgoing message. Scope is unchanged, so direct impact on separate security authorities is not indicated.

**Who is most exposed:** Internet-facing WebSocket applications and backend services using the affected library for compressed outgoing traffic are the main concern. Exposure depends on the extension being enabled and attacker-controlled input influencing large responses.

Review WebSocket logs for unusually large outgoing messages and compression negotiation.

Monitor affected processes for crashes, allocator errors or memory-corruption diagnostics.

Correlate abnormal outbound message sizes with remote sessions and subsequent restarts.

Mitigation and prioritisation

Apply the vendor’s security update promptly; confirm package status where applicability is uncertain.

Until patched, disable per-message compression if feasible and cap outgoing message sizes.

Restrict access to exposed WebSocket endpoints where business requirements allow.

Test mitigations and updates against message size and compression workflows before broad rollout.

KEV, SSVC, PoC and EPSS data are absent; verify them before setting formal priority, including whether priority 1 criteria apply.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

Platforms (2)