Junglewise Threat Intelligence

CVE-2026-12478: GNOME libsoup out-of-bounds read in WebSocket frame processing

CVE-2026-12478 · Severity: medium · CVSS 4.8 · Published 2026-07-14

Technologies: Gnome Libsoup. Vendors: Red Hat, Gnome.

Executive brief

libsoup is a networking library used by many applications to handle web communications. A flaw in how it processes WebSocket data allows a malicious server to send specially crafted messages that could cause an application to crash or potentially leak small amounts of memory. This issue occurs because a previous security fix was incomplete, leaving certain types of data transfers unprotected.

Technical details

An out-of-bounds read vulnerability exists in libsoup's WebSocket frame processing. The root cause is an incomplete fix for CVE-2026-0716 (commit 6ff7ef0), where integer overflow guards were only applied to masked frames, leaving unmasked server-to-client frames unprotected. A malicious server can exploit this by sending an unmasked frame with a payload length field near UINT64_MAX. This attack is successful when the client has 'max_incoming_payload_size' set to 0. The vulnerability can lead to a denial of service (crash) or limited information disclosure.

Affected products

  • Red Hat libsoup3 3.6.6
  • GNOME libsoup 3.6.6

Timeline

  • 2026-03-04: patched: Merge request to fix the OOB read in unmasked frames submitted to GNOME libsoup GitLab.
  • 2026-06-16: disclosed: Bug reported to Red Hat Bugzilla.
  • 2026-07-14: advisory: CVE-2026-12478 published.

References

Related threats