Feed/CVE-2026-69185
CVE-2026-69185HIGHCVSS 7.5

Socket.IO: Zero-attachment Memory Exhaustion

Published Aug 3, 2026·Updated Aug 3, 2026

NVD Description

### Impact A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. ### Patches | Version range | Used by | Fixed version | |------------------|--------------------------------------------|---------------| | `>=4.0.0 <4.2.7` | `socket.io@4.x` and `socket.io-client@4.x` | `4.2.7` | | `>=3.4.0 <3.4.5` | `socket.io@2.x` | `3.4.5` | | `<3.3.6` | `socket.io-client@2.x` | `3.3.6` | ### Workarounds There is no known workaround except upgrading to a safe version. ### For more information If you have any questions or comments about this advisory: - Open a discussion [here](https://github.com/socketio/socket.io/discussions)

Affected Packages (1)

socket.io-parserNPM
From 4.0.0
Fixed in 4.2.7

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free