Answer in brief
CVE-2026-102555 records a High severity (CVSS 8.2) vulnerability in Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding. The current sources do not mark it as known exploited. The current feed maps Red Hat/libsoup (generic), Red Hat/libsoup3 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.2. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Red Hat/libsoup (generic), Red Hat/libsoup3 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Red Hat/libsoupgeneric | * | Not reported |
| Red Hat/libsoup3generic | * | Not reported |
Published upstream
Sep 29, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 29, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 29, 2026
A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when processing a crafted data URI.
Quoted source text, attributed separately from HOL analysis.