← Volver al buscador de CVEs

CVE-2026-15709

libsoup

Descripción

A flaw was found in libsoup-s WebSocket implementation when using the permessage-deflate extension. The extension-s decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS).

CVSS 7.5EPSS 0.5479999999999999%Riesgo 0.79
Ver fuente
Publicación
2026-07-14 20:16:57
Versiones afectadas
unknown
Tipo
Librería
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H