Microsoft Security Response Center guidance
Release Notes
Vulnerability intelligence
CVE-2026-102557 and is rated High severity with a CVSS score of 8.6. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits of the underlying buffer type. A remote peer could send fragments that caused size truncation while the implementation still used the full length, leading to heap corruption or a crash.