Red Hat libsoup: denial of service
High7.5CVE-2026-15711 · Published Jul 14, 2026 · updated Sep 24, 2026
A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this by sending a non-compliant, oversized control frame. Because the parser handles this protocol violation improperly instead of throwing an immediate connection termination error, it triggers a internal processing crash, resulting in a remote denial of service (DoS) for applications utilizing libsoup WebSockets.
Affected versions
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-770
- www.cve.org/CVERecord?id=CVE-2026-15711
- nvd.nist.gov/vuln/detail/CVE-2026-15711
- access.redhat.com/errata/RHSA-2026:68234
- access.redhat.com/errata/RHSA-2026:68235
- access.redhat.com/errata/RHSA-2026:68266
- access.redhat.com/errata/RHSA-2026:68612
- access.redhat.com/errata/RHSA-2026:69108
- access.redhat.com/errata/RHSA-2026:69297
- access.redhat.com/errata/RHSA-2026:69863
- access.redhat.com/errata/RHSA-2026:70598
- access.redhat.com/errata/RHSA-2026:70599
- access.redhat.com/errata/RHSA-2026:71389
- access.redhat.com/security/cve/CVE-2026-15711
- bugzilla.redhat.com/show_bug.cgi?id=2499924
- gitlab.gnome.org/GNOME/libsoup/-/issues/515
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | A flaw was found in libsoup's WebSocket implementation | High7.5 | No fix yet |
| Jul 14 | Red Hat libsoup: denial of service | Medium5.9 | No fix yet |
| Jul 14 | Red Hat libsoup: out-of-bounds read | Medium6.5 | No fix yet |
| Jul 14 | Red Hat Enterprise Linux 10: denial of service | Medium5.9 | No fix yet |
| Jul 14 | Red Hat open5gs: out-of-bounds read | High8.6 | No fix yet |
| Jul 14 | Red Hat Enterprise Linux: integer overflow | Medium4.8 | No fix yet |