{"id":"CVE-2026-15709","title":"A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension","summary":"A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer si…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-409"],"vendor":"Red Hat","product":"libsoup3","affected":["libsoup3 (all versions)","libsoup (all versions)","libsoup (all versions)","libsoup (all versions)","libsoup (all versions)","libsoup (all versions)","libsoup (all versions)","libsoup (all versions)","libsoup (all versions)","libsoup (all versions)","libsoup (all versions)","libsoup","libsoup","libsoup (all versions)"],"patched":["enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_9","enterprise_linux_codeready_linux_builder_v_10"],"published":"2026-07-14","updated":"2026-09-23","sourceUpdated":"2026-09-23T09:17:07.833","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-15709","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:68234","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:68235","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:68612","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:69108","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:69297","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:69863","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:70598","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:70599","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-15709","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2499922","label":"secalert@redhat.com"},{"url":"https://gitlab.gnome.org/GNOME/libsoup/-/issues/511","label":"secalert@redhat.com"},{"url":"https://gitlab.gnome.org/GNOME/libsoup/-/issues/511","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15709.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-15709"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15709"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-07-15T12:58:14.451474Z"},"epss":0.00688,"epssPercentile":0.51301,"ingestedAt":"2026-09-16T19:02:30.739Z","slug":"CVE-2026-15709","body":"## Overview\n\nA flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS).\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:68235** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68235)\n- **RHSA-2026:68234** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68234)\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15709.json)\n- **RHSA-2026:68612** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68612)\n- **RHSA-2026:69297** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69297)\n- **RHSA-2026:69108** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69108)\n- **RHSA-2026:69863** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8), Red Hat Enterprise Linux BaseOS E4S (v.8.8), Red Hat Enterprise Linux BaseOS TUS (v.8.8) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69863)","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}