Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-0716

Опубликовано: 13 янв. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsoup3fixed3.6.5-9package
libsoup3no-dsatrixiepackage
libsoup3no-dsabookwormpackage
libsoup2.4removedpackage
libsoup2.4no-dsatrixiepackage
libsoup2.4no-dsabookwormpackage

Примечания

  • https://gitlab.gnome.org/GNOME/libsoup/-/issues/476

  • When fixing this issue make sure to make the fix complete to not open up CVE-2026-12478

EPSS

Процентиль: 26%
0.00329
Низкий

Связанные уязвимости

CVSS3: 4.8
ubuntu
7 месяцев назад

A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.

CVSS3: 4.8
redhat
7 месяцев назад

A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.

CVSS3: 4.8
nvd
7 месяцев назад

A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.

CVSS3: 4.8
msrc
7 месяцев назад

Libsoup: out-of-bounds read in libsoup websocket frame processing

suse-cvrf
5 месяцев назад

Security update for libsoup

EPSS

Процентиль: 26%
0.00329
Низкий