#VU122821 Buffer access with incorrect length value in libsoup - CVE-2026-0716

 

#VU122821 Buffer access with incorrect length value in libsoup - CVE-2026-0716

Published: February 13, 2026


Vulnerability identifier: #VU122821
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2026-0716
CWE-ID: CWE-805
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
libsoup
Software vendor:
Gnome Development Team

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a boundary error in process_frame() function when handling WebSocket frames if a non-default configuration is used where the maximum incoming payload size is unset. A remote attacker can send specially crafted data to the application and execute arbitrary code on the system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links