CVE-2026-69185

Summary

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

Affected Software

VendorProductVersion RangeStatus
socketiosocket.io< 3.3.6affected
socketiosocket.io>= 3.4.0, < 3.4.5affected
socketiosocket.io>= 4.0.0, < 4.2.7affected

Weaknesses

  • CWE-20: CWE-20: Improper Input Validation
  • CWE-754: CWE-754: Improper Check for Unusual or Exceptional Conditions

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References