Junglewise Threat Intelligence

CVE-2026-0716: libsoup WebSocket out-of-bounds read in frame processing

CVE-2026-0716 · Severity: medium · CVSS 4.8 · Published 2026-01-13

Technologies: Gnome Libsoup. Vendors: Gnome.

Executive brief

libsoup is a networking library used by many applications to handle web communications, including WebSocket connections. A flaw in its WebSocket frame processing can cause the library to read memory outside intended bounds when a non-standard configuration is used, potentially exposing sensitive data or causing the application to crash.

Technical details

An out-of-bounds read vulnerability exists in libsoup's WebSocket frame processing when handling incoming messages. The root cause is improper length validation when the maximum incoming payload size is unset or explicitly set to 0 (non-default configuration). This allows an attacker to send specially crafted WebSocket frames over the network that trigger reads beyond allocated buffer boundaries. The vulnerability can result in unintended memory disclosure or denial of service via application crash. Exploitation requires network access to a WebSocket endpoint using an affected libsoup version with the vulnerable configuration.

Affected products

  • GNOME libsoup

Timeline

  • 2026-01-13: disclosed

References

Related threats