Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33151

Опубликовано: 20 мар. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:socket:socket.io-parser:*:*:*:*:*:node.js:*:*
Версия до 3.3.5 (исключая)
cpe:2.3:a:socket:socket.io-parser:*:*:*:*:*:node.js:*:*
Версия от 3.4.0 (включая) до 3.4.4 (исключая)
cpe:2.3:a:socket:socket.io-parser:*:*:*:*:*:node.js:*:*
Версия от 4.0.0 (включая) до 4.2.6 (исключая)

EPSS

Процентиль: 40%
0.00514
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.

CVSS3: 5.3
redhat
5 месяцев назад

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.

CVSS3: 7.5
debian
5 месяцев назад

Socket.IO is an open source, real-time, bidirectional, event-based, co ...

github
5 месяцев назад

socket.io allows an unbounded number of binary attachments

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость кодировщика и декодировщика пакетов socket.io parser библиотеки Socket.IO, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 40%
0.00514
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo