Skip to content
Red HatCVE-2026-15711

Red Hat libsoup: denial of service

High7.5CVE-2026-15711 · Published Jul 14, 2026 · updated Sep 24, 2026

A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this by sending a non-compliant, oversized control frame. Because the parser handles this protocol violation improperly instead of throwing an immediate connection termination error, it triggers a internal processing crash, resulting in a remote denial of service (DoS) for applications utilizing libsoup WebSockets.

Red Hat advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Red Hat advisories

All Red Hat
Advisory
A flaw was found in libsoup's WebSocket implementation
High7.5Jul 14
Red Hat libsoup: denial of service
Medium5.9Jul 14
Red Hat libsoup: out-of-bounds read
Medium6.5Jul 14
Red Hat Enterprise Linux 10: denial of service
Medium5.9Jul 14
Red Hat open5gs: out-of-bounds read
High8.6Jul 14
Red Hat Enterprise Linux: integer overflow
Medium4.8Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.