


Perceptive Security
SOC/SIEM Consultancy

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can mak…
Published:
3 augustus 2026 om 00:00:00
Alert date:
3 augustus 2026 om 23:04:01
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A denial-of-service vulnerability exists in Socket.IO, a real-time bidirectional communication library. Affected versions prior to 4.2.7, 3.4.5, and 3.3.6 are vulnerable to memory exhaustion attacks. An attacker can send a specially crafted packet that causes the server to buffer a large number of binary attachments, eventually exhausting server memory. This vulnerability can be exploited remotely without authentication, making it a significant risk for any service using affected Socket.IO versions. The issue has been patched in versions 4.2.7, 3.4.5, and 3.3.6. Multiple commits were issued across different version branches to address the vulnerability. Users are strongly advised to upgrade to the fixed versions immediately. The vulnerability is tracked under CVE-2026-69185 and also documented in GitHub Security Advisory GHSA-2m8v-j782-fhvr.
Technical details
Mitigation steps:
Affected products:
Socket.IO < 4.2.7
Socket.IO < 3.4.5
Socket.IO < 3.3.6
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-69185
https://github.com/socketio/socket.io/commit/7c6ef571a00656718e9e05e3b948fd1758b2a7b4
https://github.com/socketio/socket.io/commit/9c6323e5cde41bd75df3379b5fc9293664a5f240
https://github.com/socketio/socket.io/commit/ced94ffa3ac020a8f3c14eb98a3bf34acb14d291
https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
