Socket.Io · Socket.Io · CVE-2026-59724
**Name of the Vulnerable Software and Affected Versions**
Socket.IO versions 6.5.0 through 6.6.6
**Description**
Engine.IO servers with WebTransport enabled are susceptible to a denial of service. During WebTransport upgrade handling, the server can resolve a crafted session ID, such as ` proto `, through an inherited property of the clients object, which results in a TypeError.
**Recommendations**
Update to version 6.6.7.