A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS).
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade libsoup3-debugsourceUpgrade libsoup-debuginfoUpgrade libsoup3-docUpgrade libsoup-docUpgrade libsoup-develUpgrade libsoup3-develUpgrade libsoupUpgrade libsoup3Upgrade libsoup3-debuginfoUpgrade libsoup-debugsource | Sep 30, 2026 | Jul 14, 2026 |
| Redhat_linux | — | Upgrade libsoup3-docUpgrade libsoup-debugsourceUpgrade libsoup3-debugsourceNo solution existsUpgrade libsoup-develUpgrade libsoup3-develUpgrade libsoup3Upgrade libsoup-debuginfoUpgrade libsoupUpgrade libsoup3-debuginfo | Jul 17, 2026 | Jul 14, 2026 |
| Rocky_linux | — | Upgrade libsoup-debugsourceUpgrade libsoup-develUpgrade libsoup-debuginfoUpgrade libsoup | Sep 18, 2026 | Sep 17, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub