SB2026021345 - Buffer overflow in libsoup WebSocket support
Published: February 13, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer access with incorrect length value (CVE-ID: CVE-2026-0716)
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in process_frame() function when handling WebSocket frames if a non-default configuration is used where the maximum incoming payload size is unset. A remote attacker can send specially crafted data to the application and execute arbitrary code on the system.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.