PT-2026-56488 · Socket.Io · Socket.Io
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Socket.IO versions 4.1.0 through 6.6.6
Description
The Engine.IO protocol v4 polling transport fails to properly close the HTTP response when receiving invalid binary POST requests that use the
Content-Type: application/octet-stream header. This behavior allows an unauthenticated attacker to exhaust server-side connections and sockets, potentially leading to a denial of service.Recommendations
Update to version 6.6.7.
Exploit
Fix
DoS
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Socket.Io