Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-677m-j7p3-52f9

Опубликовано: 18 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.7

Описание

socket.io allows an unbounded number of binary attachments

Impact

A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.

Patches

Version rangeUsed byFixed version
>=4.0.0 <4.2.6socket.io@4.x and socket.io-client@4.x4.2.6
>=3.4.0 <3.4.4socket.io@2.x3.4.4
<3.3.5socket.io-client@2.x3.3.5

Workarounds

There is no known workaround except upgrading to a safe version.

For more information

If you have any questions or comments about this advisory:

  • Open a discussion here

Пакеты

Наименование

socket.io-parser

npm
Затронутые версииВерсия исправления

< 3.3.5

3.3.5

Наименование

socket.io-parser

npm
Затронутые версииВерсия исправления

>= 3.4.0, < 3.4.4

3.4.4

Наименование

socket.io-parser

npm
Затронутые версииВерсия исправления

>= 4.0.0, < 4.2.6

4.2.6

EPSS

Процентиль: 41%
0.00514
Низкий

8.7 High

CVSS4

Дефекты

CWE-754

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.

CVSS3: 5.3
redhat
5 месяцев назад

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.

CVSS3: 7.5
nvd
5 месяцев назад

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.

CVSS3: 7.5
debian
5 месяцев назад

Socket.IO is an open source, real-time, bidirectional, event-based, co ...

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость кодировщика и декодировщика пакетов socket.io parser библиотеки Socket.IO, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 41%
0.00514
Низкий

8.7 High

CVSS4

Дефекты

CWE-754