Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-69185

Опубликовано: 03 авг. 2026
Источник: debian
EPSS Низкий

Описание

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-socket.io-parserfixed4.2.4+~3.1.2-1package
node-socket.io-parserno-dsatrixiepackage
node-socket.io-parserpostponedbookwormpackage
node-socket.io-parserpostponedbullseyepackage

Примечания

  • https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr

  • Fixed by: https://github.com/socketio/socket.io/commit/7c6ef571a00656718e9e05e3b948fd1758b2a7b4 (socket.io-parser@4.2.7)

  • Fixed by: https://github.com/socketio/socket.io/commit/ced94ffa3ac020a8f3c14eb98a3bf34acb14d291 (socket.io-parser@3.4.5)

  • Fixed by: https://github.com/socketio/socket.io/commit/9c6323e5cde41bd75df3379b5fc9293664a5f240 (socket.io-parser@3.3.6)

EPSS

Процентиль: 41%
0.00503
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
28 дней назад

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

CVSS3: 7.5
redhat
28 дней назад

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

CVSS3: 7.5
nvd
28 дней назад

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

CVSS3: 7.5
github
28 дней назад

Socket.IO: Zero-attachment Memory Exhaustion

EPSS

Процентиль: 41%
0.00503
Низкий