PT-2026-56487 · Socket.Io · Socket.Io

·

CVE-2026-59724

·

Published

2026-07-08

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Socket.IO versions 6.5.0 through 6.6.6
Description Engine.IO servers with WebTransport enabled are susceptible to a denial of service. During WebTransport upgrade handling, the server can resolve a crafted session ID, such as proto, through an inherited property of the clients object, which results in a TypeError.
Recommendations Update to version 6.6.7.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59724
GHSA-GR94-W7QR-F4J3
RHSA-2026:26994

Affected Products

Socket.Io