CVE-2026-102556High· 8.6▾ TwilightA flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handl…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102555High· 8.2Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding
CVE-2026-102558High· 8.6Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth
CVE-2026-102559High· 8.6Libsoup: libsoup: heap buffer overflow during websocket client-frame masking
CVE-2026-102560High· 8.6Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buffer growth
CVE-2026-102557High· 8.6A flaw was found in libsoup
CVE-2026-88815High· 7.5DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it …