Description
A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when processing a crafted data URI.
Published: 2026-09-29
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds read and application crash
Action: Apply patch
AI Analysis

Impact

The vulnerability is a heap buffer overflow caused by the libsoup function soup_uri_decode_data_uri() treating base64 data‑URI payloads as NUL‑terminated strings. When the percent‑decoded payload contains embedded NUL bytes, the function may leave the decoded length uninitialized, and g_base64_decode_inplace() returns a GBytes object whose size is based on this uninitialized value. This allows an out‑of‑bounds read or a crash when an attacker provides a crafted data URI. The weakness is a classic example of an uninitialized read (CWE‑125).

Affected Systems

The flaw is present in the libsoup libraries shipped with Red Hat Enterprise Linux versions 10, 6, 7, 8, and 9. Any application on these distributions that uses soup_uri_decode_data_uri() to handle data URIs may be affected.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. The EPSS score is not available, but the lack of a KEV listing suggests no public exploit in the wild at this time. The likely attack vector is remote, via a maliciously crafted data URI that an application processes. Once triggered, the attacker could cause a denial‑of‑service or potentially gain further escalation if the application processes untrusted data in a privileged context.

Generated by OpenCVE AI on September 29, 2026 at 22:29 UTC.

Remediation

Vendor Workaround

To mitigate this do not pass untrusted data URIs to soup_uri_decode_data_uri().


OpenCVE Recommended Actions

  • Avoid passing untrusted data URIs to soup_uri_decode_data_uri() as a temporary safeguard.
  • Update the system to the latest Red Hat Enterprise Linux release or apply any available libsoup patch that addresses the uninitialized length issue.
  • If a patch is not yet available, validate or sanitize the data URI payload before passing it to the decoding function to eliminate embedded NUL bytes.

Generated by OpenCVE AI on September 29, 2026 at 22:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when processing a crafted data URI.
Title Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-125
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-29T18:17:40.151Z

Reserved: 2026-09-29T13:18:55.028Z

Link: CVE-2026-102555

cve-icon Vulnrichment

Updated: 2026-09-29T18:17:33.347Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:07.977

Modified: 2026-09-29T21:29:07.663

Link: CVE-2026-102555

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T22:30:19Z

Weaknesses