OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102556

HIGH · CVSS 8.6 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A vulnerability in libsoup affects applications that utilize the WebSocket Pong frame handling, where the emitted signal incorrectly uses a GByteArray pointer instead of the expected GBytes type. This flaw can lead to heap corruption or application crashes when processing specially crafted Pong frames. Developers and security teams using libsoup in their applications should prioritize addressing this issue to mitigate potential exploitation risks.

CVE
CVE-2026-102556
Severity
HIGH
CVSS
8.6
EPSS
0.22%

Original NVD Description

A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong.