Issued at: 2026-09-17
Updated at: 2026-09-17
Advisory content derived from Red Hat RHSA-2026:68234, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Moderate: libsoup security update
Description
The libsoup packages provide an HTTP client and server library for GNOME.
Security Fix(es):
* SoupWebsocketExtensionDeflate: libsoup: libsoup: WebSocket permessage-deflate Unbounded Decompression Remote Denial of Service (CVE-2026-15709)
* libsoup: SoupWebsocketConnection: libsoup: WebSocket remote denial of service via oversized control frame protocol violation (CVE-2026-15711)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.