CVE-2026-102556
ADVISORY - nistSummary
A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong.
Common Weakness Enumeration (CWE)
ADVISORY - nist
Access of Resource Using Incompatible Type ('Type Confusion')
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-102556
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
8.6highDebian
CREATED
UPDATED
ADVISORY IDCVE-2026-102556
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-