---
id: CVE-2026-15709
title: >-
  A flaw was found in libsoup's WebSocket implementation when using the
  permessage-deflate extension
summary: >-
  A flaw was found in libsoup's WebSocket implementation when using the
  permessage-deflate extension. The extension's decompression loop (inflate())
  processes data in chunks without enforcing an upper boundary limit on the
  output buffer si…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-409
vendor: Red Hat
product: libsoup3
affected:
  - libsoup3 (all versions)
  - libsoup3 (all versions)
  - libsoup (all versions)
  - libsoup (all versions)
  - libsoup (all versions)
  - libsoup (all versions)
  - libsoup (all versions)
  - libsoup (all versions)
  - libsoup (all versions)
  - libsoup (all versions)
  - libsoup (all versions)
  - libsoup (all versions)
  - libsoup
  - libsoup
  - libsoup (all versions)
patched:
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_9
  - enterprise_linux_codeready_linux_builder_v_10
published: '2026-07-14'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T10:17:34.317'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15709'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:68234'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68235'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68612'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:69108'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:69297'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:69863'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:70598'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:70599'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:71389'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-15709'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2499922'
    label: secalert@redhat.com
  - url: 'https://gitlab.gnome.org/GNOME/libsoup/-/issues/511'
    label: secalert@redhat.com
  - url: 'https://gitlab.gnome.org/GNOME/libsoup/-/issues/511'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15709.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-15709'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15709'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-07-15T12:58:14.451474Z'
epss: 0.00883
epssPercentile: 0.57408
ingestedAt: '2026-09-16T19:02:30.739Z'
---

## Overview

A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:68235** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68235)
- **RHSA-2026:68234** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68234)
- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15709.json)
- **RHSA-2026:68612** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68612)
- **RHSA-2026:69297** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69297)
- **RHSA-2026:69108** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69108)
- **RHSA-2026:69863** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8), Red Hat Enterprise Linux BaseOS E4S (v.8.8), Red Hat Enterprise Linux BaseOS TUS (v.8.8) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69863)
