CVE-2026-102555: Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding
A flaw was found in libsoup. The soupuridecodedatauri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling gbase64decodeinplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when processing a crafted data URI.
Other sources
A heap buffer overflow condition was found in libsoup's soupuridecodedatauri().
After percent-decoding a data URI payload marked ;base64, the code called gbase64decodeinplace(), which measures input with strlen(). Percent-decoded content can contain embedded NUL bytes (for example data:;base64,A%00B), so the measured length was too short. gbase64decodeinplace() returned without writing a valid output length; the uninitialized length was then stored as the size of the returned GBytes, allowing callers to read past the allocation.
Fixed upstream by decoding with gbase64decodestep() using the real buffer length (commit e4f03226, libsoup 3.7.3).
References: https://gitlab.gnome.org/GNOME/libsoup/-/workitems/554 (Bug 1) https://gitlab.gnome.org/GNOME/libsoup/-/commit/e4f03226
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libsoupto a version that resolves this vulnerability.Fixed in 3.7.3Patch e4f03226
Event History
Frequently Asked Questions
What input is required to trigger the flaw?
An attacker needs to cause an application to process a crafted base64 data URI whose percent-decoded payload contains an embedded NUL byte, such as data:;base64,A%00B. No authentication or user interaction is required according to the supplied severity vector.
What is the likely impact on an affected application?
The invalid decoded length can be used as the size of a returned GBytes object, allowing subsequent callers to read beyond the allocated buffer. This can result in an application crash and exposes a potential out-of-bounds read.
Which upstream version includes the fix?
The issue was fixed upstream in libsoup 3.7.3. The fix replaces the NUL-terminated decoding path with g_base64_decode_step() using the actual buffer length.