suse · CVE-2026-0716

Quick triage

Priority: medium Published: 2026-03-05 00:19:55 UTC Updated: 2026-04-18 09:02:01 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2026-0716 severity moderate: SUSE including 82 source package names (13.2-9.12:libpython3_11-1_0-3.11.13-1.1, 13.2-9.12:python311-base-3.11.13-1.1, …), 222 product×package rows across 46 product lines (Container suse/sl-micro/6.0/baremetal-os-container, Container suse/sl-micro/6.0/toolbox, … (46 product lines)): Fixed 218, First Fixed 4.

Description:

A flaw was found in libsoup's WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup's WebSocket support with this configuration may be impacted.

cvelogic Threat Intelligence