Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2m8v-j782-fhvr

Опубликовано: 03 авг. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Socket.IO: Zero-attachment Memory Exhaustion

Impact

A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.

Patches

Version rangeUsed byFixed version
>=4.0.0 <4.2.7socket.io@4.x and socket.io-client@4.x4.2.7
>=3.4.0 <3.4.5socket.io@2.x3.4.5
<3.3.6socket.io-client@2.x3.3.6

Workarounds

There is no known workaround except upgrading to a safe version.

For more information

If you have any questions or comments about this advisory:

  • Open a discussion here

Пакеты

Наименование

socket.io-parser

npm
Затронутые версииВерсия исправления

>= 4.0.0, < 4.2.7

4.2.7

Наименование

socket.io-parser

npm
Затронутые версииВерсия исправления

>= 3.4.0, < 3.4.5

3.4.5

Наименование

socket.io-parser

npm
Затронутые версииВерсия исправления

< 3.3.6

3.3.6

EPSS

Процентиль: 28%
0.00346
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-754

Связанные уязвимости

CVSS3: 7.5
ubuntu
28 дней назад

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

CVSS3: 7.5
redhat
28 дней назад

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

CVSS3: 7.5
nvd
28 дней назад

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

CVSS3: 7.5
debian
28 дней назад

Socket.IO enables bidirectional and low-latency communication for ever ...

EPSS

Процентиль: 28%
0.00346
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-754