CVE-2026-69185
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| socketio | socket.io | < 3.3.6 | affected |
| socketio | socket.io | >= 3.4.0, < 3.4.5 | affected |
| socketio | socket.io | >= 4.0.0, < 4.2.7 | affected |
Weaknesses
- CWE-20: CWE-20: Improper Input Validation
- CWE-754: CWE-754: Improper Check for Unusual or Exceptional Conditions
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
- https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr
- https://github.com/socketio/socket.io/commit/7c6ef571a00656718e9e05e3b948fd1758b2a7b4
- https://github.com/socketio/socket.io/commit/9c6323e5cde41bd75df3379b5fc9293664a5f240
- https://github.com/socketio/socket.io/commit/ced94ffa3ac020a8f3c14eb98a3bf34acb14d291
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.