Libsoup: out-of-bounds read in libsoup websocket frame processing
Published Jan 13, 2026
4.8
MEDIUMCVSS 3.1
EPSS 0.39%
Description
A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.
Affected products
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | affected | |
| Red Hat | Red Hat Enterprise Linux 7 | affected | |
| Red Hat | Red Hat Enterprise Linux 8 | affected | |
| Red Hat | Red Hat Enterprise Linux 9 | affected |
No data.
No data.
Red Hat Enterprise Linux 10
libsoup3
Fix deferred
Red Hat Enterprise Linux 6
libsoup
Not affected
Red Hat Enterprise Linux 7
libsoup
Fix deferred
Red Hat Enterprise Linux 8
libsoup
Fix deferred
Red Hat Enterprise Linux 9
libsoup
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | libsoup3 | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | libsoup | Not affected | n/a |
| Red Hat Enterprise Linux 7 | libsoup | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | libsoup | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | libsoup | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this issue, applications utilizing libsoup's WebSocket support should ensure that the `max_incoming_payload_size` is explicitly set to a non-zero value. This prevents the library from processing WebSocket frames with an unset or zero maximum payload size, which can lead to out-of-bounds reads. Consult application-specific documentation for configuring libsoup parameters.
Red Hat statement
This vulnerability is rated Moderate for Red Hat because it requires a non-default configuration where `max_incoming_payload_size` is explicitly set to 0 or unset in libsoup's WebSocket frame processing. In typical Red Hat deployments, this configuration is not enabled by default, limiting the exposure to memory disclosure or application instability.
Red Hat mitigation
To mitigate this issue, applications utilizing libsoup's WebSocket support should ensure that the `max_incoming_payload_size` is explicitly set to a non-zero value. This prevents the library from processing WebSocket frames with an unset or zero maximum payload size, which can lead to out-of-bounds reads. Consult application-specific documentation for configuring libsoup parameters.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-0716 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2427896 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-2591 Advisory
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/476
- https://nvd.nist.gov/vuln/detail/CVE-2026-0716
- https://www.cve.org/CVERecord?id=CVE-2026-0716
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-0716 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2427896 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-2591 | Advisory | |
| https://gitlab.gnome.org/GNOME/libsoup/-/issues/476 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2026-0716 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-0716 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data