GHSA-cj4p-f4hv-cp74HighCVSS 8.6

A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large...

Published
September 29, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full length, causing a heap buffer overflow.

🔗 References (4)