CVE-2026-12478

EUVD-2026-43651
The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked frame with a payload length near UINT64_MAX to trigger an OOB read in a libsoup-based client when max_incoming_payload_size is set to 0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 32.96%
Debian logo
Debian Releases
Debian Product
Codename
libsoup2.4
bookworm
2.74.3-1+deb12u1
fixed
bullseye
2.72.0-2
fixed
bullseye (security)
2.72.0-2+deb11u3
fixed
trixie
2.74.3-10.1
fixed
libsoup3
bookworm
3.2.3-0+deb12u2
fixed
forky
vulnerable
sid
vulnerable
trixie
3.6.5-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libsoup3
jammy
needs-triage
noble
needs-triage
resolute
needs-triage