Back

MEDIUM

Libsoup: out-of-bounds read in libsoup websocket frame processing

Published Jan 13, 2026

Description

A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.

Affected products

Remediation

Vendor solution

To mitigate this issue, applications utilizing libsoup's WebSocket support should ensure that the `max_incoming_payload_size` is explicitly set to a non-zero value. This prevents the library from processing WebSocket frames with an unset or zero maximum payload size, which can lead to out-of-bounds reads. Consult application-specific documentation for configuring libsoup parameters.

Red Hat statement

This vulnerability is rated Moderate for Red Hat because it requires a non-default configuration where `max_incoming_payload_size` is explicitly set to 0 or unset in libsoup's WebSocket frame processing. In typical Red Hat deployments, this configuration is not enabled by default, limiting the exposure to memory disclosure or application instability.

Red Hat mitigation

To mitigate this issue, applications utilizing libsoup's WebSocket support should ensure that the `max_incoming_payload_size` is explicitly set to a non-zero value. This prevents the library from processing WebSocket frames with an unset or zero maximum payload size, which can lead to out-of-bounds reads. Consult application-specific documentation for configuring libsoup parameters.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Jan 13, 2026
Updated Sep 16, 2026
Reserved Jan 8, 2026

CISA Vulnrichment

Updated Jan 14, 2026

NVD

Status Deferred
Modified Sep 16, 2026

Red Hat

Severity Moderate
Public date Jan 8, 2026
Bugzilla 2427896

ENISA EUVD

Assigner redhat
Published Jan 13, 2026
Updated Sep 16, 2026

GitHub

No data