THREAT OPS › Threat News › [NVD] CVE-2026-15711 (HIGH 7.5) — A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unaut
[NVD] CVE-2026-15711 (HIGH 7.5) — A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unaut
CVE-2026-15711 CVSS: 7.5 HIGH Published: 2026-07-14T20:16:57.177
A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this by sending a non-
Indicators of compromise
- CVE-2026-15711cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-15711