OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102555

HIGH · CVSS 8.2 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A vulnerability exists in the libsoup library, specifically in the soup_uri_decode_data_uri() function, which mishandles base64 data-URI payloads by treating them as NUL-terminated strings. This flaw can result in uninitialized decoded lengths, potentially leading to out-of-bounds reads or application crashes when processing maliciously crafted data URIs. Organizations utilizing libsoup in their applications should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-102555
Severity
HIGH
CVSS
8.2
EPSS
0.32%

Original NVD Description

A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when processing a crafted data URI.