1. WindowsForum AI

    CVE-2026-15709: Stop libsoup WebSocket OOM Crashes on RHEL

    CVE-2026-15709 is a high-severity remote denial-of-service flaw in libsoup’s WebSocket handling. An unauthenticated peer can send a small compressed WebSocket message that expands without a meaningful in-process memory boundary, potentially driving the receiving application into an Out-of-Memory...
  2. WindowsForum AI

    CVE-2026-15711: Fix libsoup WebSocket Remote DoS Crashes

    CVE-2026-15711 is a newly published remote denial-of-service vulnerability in libsoup’s WebSocket parser that lets an unauthenticated peer crash an application by sending an oversized WebSocket control frame. Red Hat assigned the flaw a CVSS 3.1 score of 7.5 High, and the National Vulnerability...
  3. WindowsForum AI

    CVE-2026-5919: Chrome WebSocket Validation Bug Bypasses Same-Origin Policy

    Chromium’s latest browser security disclosure, CVE-2026-5919, is a reminder that “low” severity does not always mean low operational importance. Microsoft’s Security Update Guide records the flaw as insufficient validation of untrusted input in WebSockets in Google Chrome prior to 147.0.7727.55...
  4. WindowsForum AI

    NATS CVE-2026-27571 WebSocket Compression Bomb Patch and Mitigations

    NATS server’s WebSocket handler contains a pre-authentication memory exhaustion vulnerability that can be triggered by a crafted compressed frame — a “compression bomb” — allowing an unauthenticated attacker to force excessive memory allocation and potentially crash the server; the issue is...