A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray… (CVE-2026-102559)
A heap buffer overflow vulnerability exists in libsoup when constructing a masked WebSocket client frame for very large outgoing payloads. The flaw occurs because size values passed to GByteArray allocation APIs may be truncated, while the masking routine uses the full length, leading to heap corruption or denial of service in the sending process. Exploitation requires sending an extremely large WebSocket message, which may be possible if the application allows attacker-controlled message sizes. The vulnerability is rated high severity with a CVSS score of 8.6.
AI Analysis
Technical Summary
CVE-2026-102559 is a heap buffer overflow vulnerability in libsoup's WebSocket client implementation. When constructing a masked WebSocket client frame for a very large outgoing payload, the size values passed to GByteArray allocation APIs can be truncated, but the masking routine still uses the full payload length. This mismatch causes a heap buffer overflow, potentially leading to heap corruption or denial of service in the sending process. The issue requires an attacker to cause the client to send an extremely large message, which may be feasible if the application-level message size is influenced by an attacker. The vulnerability is classified under CWE-125 (Out-of-bounds Read) and has a CVSS 3.1 base score of 8.6 (high).
Potential Impact
The vulnerability can cause heap corruption or denial of service (crash or restart) in the process sending the WebSocket message. Confidentiality and integrity impacts are rated low, but availability impact is high. Exploitation requires network access with no privileges or user interaction needed. An attacker able to send very large WebSocket messages may trigger this flaw, potentially causing application crashes or memory corruption.
Mitigation Recommendations
Red Hat advises enforcing application-level limits on outgoing WebSocket message sizes to mitigate this vulnerability. Specifically, do not send untrusted bulk data as a single WebSocket message. No official patch or fix is currently confirmed; therefore, patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray… (CVE-2026-102559)
Description
A heap buffer overflow vulnerability exists in libsoup when constructing a masked WebSocket client frame for very large outgoing payloads. The flaw occurs because size values passed to GByteArray allocation APIs may be truncated, while the masking routine uses the full length, leading to heap corruption or denial of service in the sending process. Exploitation requires sending an extremely large WebSocket message, which may be possible if the application allows attacker-controlled message sizes. The vulnerability is rated high severity with a CVSS score of 8.6.
CVSS v3.1
Score 8.6high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-102559 is a heap buffer overflow vulnerability in libsoup's WebSocket client implementation. When constructing a masked WebSocket client frame for a very large outgoing payload, the size values passed to GByteArray allocation APIs can be truncated, but the masking routine still uses the full payload length. This mismatch causes a heap buffer overflow, potentially leading to heap corruption or denial of service in the sending process. The issue requires an attacker to cause the client to send an extremely large message, which may be feasible if the application-level message size is influenced by an attacker. The vulnerability is classified under CWE-125 (Out-of-bounds Read) and has a CVSS 3.1 base score of 8.6 (high).
Potential Impact
The vulnerability can cause heap corruption or denial of service (crash or restart) in the process sending the WebSocket message. Confidentiality and integrity impacts are rated low, but availability impact is high. Exploitation requires network access with no privileges or user interaction needed. An attacker able to send very large WebSocket messages may trigger this flaw, potentially causing application crashes or memory corruption.
Mitigation Recommendations
Red Hat advises enforcing application-level limits on outgoing WebSocket message sizes to mitigate this vulnerability. Specifically, do not send untrusted bulk data as a single WebSocket message. No official patch or fix is currently confirmed; therefore, patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-cj4p-f4hv-cp74
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-102559"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abc27bd680226ef6846f7e7
Added to database: 09/29/2026, 21:03:57 UTC
Last enriched: 09/29/2026, 21:15:56 UTC
Last updated: 09/30/2026, 03:31:54 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.