OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102560

HIGH · CVSS 8.6 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A vulnerability in libsoup affects the permessage-deflate WebSocket extension, which can lead to a heap buffer overflow when handling large outgoing messages due to improper size calculations. This flaw may allow an attacker to execute arbitrary code or crash the application, posing significant risks to systems utilizing this library. Organizations that implement libsoup in their applications should prioritize patching this vulnerability to mitigate potential exploitation.

CVE
CVE-2026-102560
Severity
HIGH
CVSS
8.6
EPSS
0.30%

Original NVD Description

A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could wrap, causing zlib to write past the allocated buffer and resulting in a heap buffer overflow.