Redpacketsecurity Critical Heap Buffer Overflows in libsoup WebSocket Handling
Article Content
- •CVE-2026-102559 and CVE-2026-102560 both involve heap buffer overflows in libsoup.
- •Exploitation requires sending large WebSocket messages, potentially influenced by attackers.
- •Mitigation includes enforcing message size limits and disabling unnecessary WebSocket features.
Two critical vulnerabilities were identified in libsoup affecting WebSocket handling. CVE-2026-102559 involves a heap buffer overflow when constructing masked WebSocket frames for large outgoing payloads, while CVE-2026-102560 occurs during the compression of large messages with the permessage-deflate extension. Both vulnerabilities are rated Important and could lead to heap corruption or denial of service. Exploitation requires the ability to send large messages, potentially influenced by attacker-controlled input. Affected systems include applications using libsoup for WebSocket connections. Mitigation strategies include enforcing message size limits and disabling unnecessary WebSocket extensions. Both CVEs were published on 2026-09-29.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Red Hat and CVE-2026-102559 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…