GHSA-fc8r-xmg7-v58hHighCVSS 8.6

A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray,...

Published
September 29, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits of the underlying buffer type. A remote peer could send fragments that caused size truncation while the implementation still used the full length, leading to heap corruption or a crash.

🔗 References (4)