top of page
perceptive_background_267k.jpg

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can mak…

Published:

3 augustus 2026 om 00:00:00

Alert date:

3 augustus 2026 om 23:04:01

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

A denial-of-service vulnerability exists in Socket.IO, a real-time bidirectional communication library. Affected versions prior to 4.2.7, 3.4.5, and 3.3.6 are vulnerable to memory exhaustion attacks. An attacker can send a specially crafted packet that causes the server to buffer a large number of binary attachments, eventually exhausting server memory. This vulnerability can be exploited remotely without authentication, making it a significant risk for any service using affected Socket.IO versions. The issue has been patched in versions 4.2.7, 3.4.5, and 3.3.6. Multiple commits were issued across different version branches to address the vulnerability. Users are strongly advised to upgrade to the fixed versions immediately. The vulnerability is tracked under CVE-2026-69185 and also documented in GitHub Security Advisory GHSA-2m8v-j782-fhvr.

Technical details

Mitigation steps:

Affected products:

Socket.IO < 4.2.7
Socket.IO < 3.4.5
Socket.IO < 3.3.6

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page