← Πίσω στην αναζήτηση CVE

CVE-2026-15711

libsoup

Περιγραφή

A vulnerability was found in libsoup-s WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this by sending a non-compliant, oversized control frame. Because the parser handles this protocol violation improperly instead of throwing an immediate connection termination error, it triggers a internal processing crash, resulting in a remote denial of service (DoS) for applications utilizing libsoup WebSockets.

CVSS 7.5EPSS 0.43099999999999994%Κίνδυνος 0.78
Προβολή πηγής
Δημοσίευση
2026-07-14 20:16:57
Επηρεαζόμενες εκδόσεις
unknown
Τύπος
Βιβλιοθήκη
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H