CVE Vulnerabilities

CVE-2026-15709

Improper Handling of Highly Compressed Data (Data Amplification)

Published: Jul 14, 2026 | Modified: Sep 24, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in libsoups WebSocket implementation when using the permessage-deflate extension. The extensions decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS).

Weakness

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatlibsoup3-0:3.6.5-3.el10_2.14*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatlibsoup3-0:3.6.5-3.el10_0.17*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatlibsoup-0:2.62.3-2.el8_4.10*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatlibsoup-0:2.62.3-2.el8_4.10*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatlibsoup-0:2.62.3-2.el8_6.10*
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnRedHatlibsoup-0:2.62.3-2.el8_6.10*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatlibsoup-0:2.62.3-3.el8_8.11*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatlibsoup-0:2.62.3-3.el8_8.11*
Red Hat Enterprise Linux 9RedHatlibsoup-0:2.72.0-16.el9_8.3*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatlibsoup-0:2.72.0-8.el9_2.13*
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsRedHatlibsoup-0:2.72.0-8.el9_4.12*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatlibsoup-0:2.72.0-10.el9_6.9*

References