VYPR
Medium severity5.9NVD Advisory· Published Jul 14, 2026· Updated Jul 15, 2026

CVE-2026-15712

CVE-2026-15712

Description

A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the library processes an HTTP/2 GOAWAY frame, it improperly handles the "Additional Debug Data" payload by assuming the data stream is a safely NUL-terminated C-string. Because the parser lacks strict length-boundary verification before reading this data, a remote, unauthenticated attacker can intentionally send a malformed GOAWAY frame missing the appropriate null delimiter. This causes the library to read past the end of the allocated buffer, triggering an application crash that results in a denial of service (DoS), or potentially exposing fragments of memory contents.

Affected products

2
  • GNOME Foundation/Libsoupinferred2 versions
    >=3.0,<3.7.0+ 1 more
    • (no CPE)range: >=3.0,<3.7.0
    • (no CPE)range: 3.0 to 3.7.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.