OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102559

HIGH · CVSS 8.6 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A heap buffer overflow vulnerability exists in libsoup when handling large outgoing payloads in masked WebSocket client frames, leading to potential memory corruption. This flaw could be exploited to execute arbitrary code or crash the application, posing a significant risk to systems utilizing libsoup for WebSocket communication. Organizations using libsoup should prioritize patching this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-102559
Severity
HIGH
CVSS
8.6
EPSS
0.30%

Original NVD Description

A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full length, causing a heap buffer overflow.