OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102558

HIGH · CVSS 8.6 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A vulnerability in libsoup allows an attacker to exploit the max-incoming-payload-size setting, which, when set to unlimited (0), can lead to a heap buffer overflow due to uncontrolled growth of the SoupWebsocketConnection's incoming GByteArray. This could enable remote code execution or denial of service, making it critical for developers and organizations utilizing libsoup in their applications to prioritize patching this flaw. Immediate action is recommended to mitigate potential exploitation risks.

CVE
CVE-2026-102558
Severity
HIGH
CVSS
8.6
EPSS
0.30%

Original NVD Description

A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer overflow while reading frame data.