CVE-2026-102559

A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full length, causing a heap buffer overflow.

  • Published Sep 29, 2026
  • CVSS 8.6 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-102559 at the National Vulnerability Database