OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102557

HIGH · CVSS 8.6 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A vulnerability in libsoup allows remote attackers to exploit improperly handled fragmented WebSocket messages, potentially leading to heap corruption or application crashes due to size truncation. This issue affects unspecified products utilizing libsoup, and organizations relying on this library should prioritize patching to mitigate the risk of remote exploitation.

CVE
CVE-2026-102557
Severity
HIGH
CVSS
8.6
EPSS
0.22%

Original NVD Description

A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits of the underlying buffer type. A remote peer could send fragments that caused size truncation while the implementation still used the full length, leading to heap corruption or a crash.