Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-33151

Опубликовано: 20 мар. 2026
Источник: debian
EPSS Низкий

Описание

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-socket.io-parserfixed4.2.1+~3.1.0-4package
node-socket.io-parserno-dsatrixiepackage
node-socket.io-parserno-dsabookwormpackage
node-socket.io-parserpostponedbullseyepackage

Примечания

  • https://github.com/socketio/socket.io/security/advisories/GHSA-677m-j7p3-52f9

  • Fixed by: https://github.com/socketio/socket.io/commit/b25738c416c4e32fbff62ee182afa8f6d0dacf78 (main)

  • Fixed by: https://github.com/socketio/socket.io/commit/719f9ebab0772ffb882bd614b387e585c1aa75d4 (socket.io-parser@3.4.4)

  • Fixed by: https://github.com/socketio/socket.io/commit/9d39f1f080510f036782f2177fac701cc041faaf (socket.io-parser@3.3.5)

EPSS

Процентиль: 41%
0.00514
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.

CVSS3: 5.3
redhat
5 месяцев назад

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.

CVSS3: 7.5
nvd
5 месяцев назад

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.

github
5 месяцев назад

socket.io allows an unbounded number of binary attachments

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость кодировщика и декодировщика пакетов socket.io parser библиотеки Socket.IO, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 41%
0.00514
Низкий