Skip to content
Critical Heap Buffer Overflows in libsoup WebSocket Handling

Critical Heap Buffer Overflows in libsoup WebSocket Handling

First seen 29 Sep 2026, 21:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 21:05 UTC
  • •CVE-2026-102559 and CVE-2026-102560 both involve heap buffer overflows in libsoup.
  • •Exploitation requires sending large WebSocket messages, potentially influenced by attackers.
  • •Mitigation includes enforcing message size limits and disabling unnecessary WebSocket features.

Two critical vulnerabilities were identified in libsoup affecting WebSocket handling. CVE-2026-102559 involves a heap buffer overflow when constructing masked WebSocket frames for large outgoing payloads, while CVE-2026-102560 occurs during the compression of large messages with the permessage-deflate extension. Both vulnerabilities are rated Important and could lead to heap corruption or denial of service. Exploitation requires the ability to send large messages, potentially influenced by attacker-controlled input. Affected systems include applications using libsoup for WebSocket connections. Mitigation strategies include enforcing message size limits and disabling unnecessary WebSocket extensions. Both CVEs were published on 2026-09-29.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-29
CVE-2026-102559 published
A heap buffer overflow vulnerability in libsoup was disclosed, affecting WebSocket client frame construction.
access.redhat.com
2026-09-29
CVE-2026-102560 published
A heap buffer overflow vulnerability in libsoup was disclosed, affecting WebSocket compression with permessage-deflate.
access.redhat.com

More articles in this cluster (4)

Following this threat?

Track Red Hat and CVE-2026-102559 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed