THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-15709 (HIGH 7.5) — A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compr

[NVD] CVE-2026-15709 (HIGH 7.5) — A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compr

lownvdPublished 2026-07-14

CVE-2026-15709 CVSS: 7.5 HIGH Published: 2026-07-14T20:16:57.027

A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fai

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-15709